Flatpak update addressing two vulnerabilities

Corrective updates are available for the Flatpak 1.14.4, 1.12.8, 1.10.8, and 1.15.4 packaging tools, which address two vulnerabilities:

  • CVE-2023-28100 - The possibility of copying and pasting text into the virtual console input buffer through manipulations with ioctl TIOCLINUX when installing a malicious flatpak package prepared by an attacker. For example, the vulnerability could be exploited to execute arbitrary commands in the console after the installation of a third-party package is completed. The issue manifests only in the classic virtual console (/dev/tty1, /dev/tty2, etc.) and does not affect sessions in xterm, gnome-terminal, Konsole, and other graphical terminals. The vulnerability is not specific to flatpak and can be used to attack other applications; similar vulnerabilities that allowed character substitution through the ioctl interface TIOCSTI were previously found in /bin/sandbox and snap.
  • CVE-2023-28101 - The possibility of using escape sequences in the permissions list within the package metadata to conceal the terminal output information about the requested extended permissions during the installation or update of the package via the command line interface. Attackers can exploit this vulnerability to mislead users about the permissions used in the package. Graphical interfaces for installing Flatpak packages, such as GNOME Software and KDE Plasma Discover, are not affected by this issue.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster