Advisories ยป MGASA-2021-0143

Updated flatpak packages fix security vulnerabilities

Publication date: 18 Mar 2021
Modification date: 18 Mar 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2021-21261 , CVE-2021-21381

Description

Sandbox escape where a malicious application can execute code outside the
sandbox by controlling the environment of the "flatpak run" command when
spawning a sub-sandbox (CVE-2021-21261).

A potential attack where a flatpak application could use custom formatted
.desktop files to gain access to files on the host system (CVE-2021-21381).

The update also removes the unnecessary flatpak-tests subpackage.
                

References

SRPMS

7/core