Lucene search

K
redosRedosROS-20240627-04
HistoryJun 27, 2024 - 12:00 a.m.

ROS-20240627-04

2024-06-2700:00:00
redos.red-soft.ru
9
flatpak
vulnerability
ioctl
application
management
command buffer
exploitation
attacker
arbitrary code
app
permissions
remote
data integrity
unix

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

6.9

Confidence

Low

A vulnerability in the ioctl component of the Flatpak application and environment management tool is related to
copying text from the virtual console and pasting it into the command buffer, from which the command can be
run after exiting the Flatpak application. Exploitation of the vulnerability could allow an attacker to
execute arbitrary code

A vulnerability in the App component of the Flatpak application and environment management tool is related to elevating
and hiding permissions. Exploitation of the vulnerability could allow an attacker acting remotely,
Impact data integrity

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64flatpak< 1.10.9-1UNKNOWN

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

6.9

Confidence

Low