CVE-2018-6560
—CVSS 3.0
8.8 high
EPSS
<1%p35
Published
()
Modified
Description
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
In the news0 stories
No ingested article mentions this CVE yet.