flatpak-1.6.2-6.el8
エラータID: AXSA:2021-1632:06
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.
Security Fix(es):
* flatpak: "file forwarding" feature can be used to gain unprivileged access to files (CVE-2021-21381)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2021-21381
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to gain access to files that would not ordinarily be allowed by the app's permissions. By putting the special tokens `@@` and/or `@@u` in the Exec field of a Flatpak app's .desktop file, a malicious app publisher can trick flatpak into behaving as though the user had chosen to open a target file with their Flatpak app, which automatically makes that file available to the Flatpak app. This is fixed in version 1.10.2. A minimal solution is the first commit "`Disallow @@ and @@U usage in desktop files`". The follow-up commits "`dir: Reserve the whole @@ prefix`" and "`dir: Refuse to export .desktop files with suspicious uses of @@ tokens`" are recommended, but not strictly required. As a workaround, avoid installing Flatpak apps from untrusted sources, or check the contents of the exported `.desktop` files in `exports/share/applications/*.desktop` (typically `~/.local/share/flatpak/exports/share/applications/*.desktop` and `/var/lib/flatpak/exports/share/applications/*.desktop`) to make sure that literal filenames do not follow `@@` or `@@u`.
Update packages.
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to gain access to files that would not ordinarily be allowed by the app's permissions. By putting the special tokens `@@` and/or `@@u` in the Exec field of a Flatpak app's .desktop file, a malicious app publisher can trick flatpak into behaving as though the user had chosen to open a target file with their Flatpak app, which automatically makes that file available to the Flatpak app. This is fixed in version 1.10.2. A minimal solution is the first commit "`Disallow @@ and @@U usage in desktop files`". The follow-up commits "`dir: Reserve the whole @@ prefix`" and "`dir: Refuse to export .desktop files with suspicious uses of @@ tokens`" are recommended, but not strictly required. As a workaround, avoid installing Flatpak apps from untrusted sources, or check the contents of the exported `.desktop` files in `exports/share/applications/*.desktop` (typically `~/.local/share/flatpak/exports/share/applications/*.desktop` and `/var/lib/flatpak/exports/share/applications/*.desktop`) to make sure that literal filenames do not follow `@@` or `@@u`.
N/A
SRPMS
- flatpak-1.6.2-6.el8.src.rpm
MD5: a9e56f0f9f0f14eabe39c5b66640ebc9
SHA-256: 8ab6005cde4cd24345a269998bfca5a7cfa2fcc501a3555a318b392949449c91
Size: 1.31 MB
Asianux Server 8 for x86_64
- flatpak-1.6.2-6.el8.x86_64.rpm
MD5: 9a27fed0d8b4c80d71621f08a2b0cf21
SHA-256: 3e8582b9f1a7d6ff9a87b4a1bb8c2b7ed0c2a993879b786575e505287ae1079f
Size: 1.47 MB - flatpak-libs-1.6.2-6.el8.x86_64.rpm
MD5: f65e3d1513d04469dcec1410154b00b0
SHA-256: f46ed31d50c1229780316b5055e05b846b52277f15359b6d1f4b13949d41aaf1
Size: 412.76 kB - flatpak-selinux-1.6.2-6.el8.noarch.rpm
MD5: eb6b0f5ed1315ce9a1379d5876640ea5
SHA-256: ca5fc697184d62244155e6c7d8b2b7b89baae9f20f5349d3f1980a83583c26b0
Size: 25.28 kB - flatpak-session-helper-1.6.2-6.el8.x86_64.rpm
MD5: 7ff1504a5f30f27dda3a80ad569057c8
SHA-256: 4c2866a9645b0a135f49f7748b1e1b04689bea2fb1caa97d997bda574f3f22c0
Size: 73.48 kB - flatpak-libs-1.6.2-6.el8.i686.rpm
MD5: 596cabc57ab9c5f3d97371beba1d0675
SHA-256: 9cb48d89abd6f16c54ac60b18e551a8a8a7683827c5197f51f530392933f8f91
Size: 438.47 kB