← Back to CVE List

CVE-2018-6560

Published: 2018-02-02T14:29Z
Last Modified: 2024-11-21T04:10Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt