CVE-2018-6560
Publication date 2 February 2018
Last updated 17 July 2025
Ubuntu priority
Cvss 3 Severity Score
Description
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| flatpak | 18.04 LTS bionic |
Not affected
|
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
8.8 · High
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H