• [SECURITY] [DSA 5749-1] flatpak security update

    From Salvatore Bonaccorso@21:1/5 to All on Wed Aug 14 22:50:02 2024
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-5749-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 14, 2024 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : flatpak
    CVE ID : CVE-2024-42472

    Chris Williams discovered a flaw in the handling of mounts for
    persistent directories in Flatpak, an application deployment framework
    for desktop apps. A malicious or compromised Flatpak app using
    persistent directories could take advantage of this flaw to access files outside of the sandbox.

    Details can be found in the upstream advisory at https://github.com/flatpak/flatpak/security/advisories/GHSA-7hgv-f2j8-xw87

    For the stable distribution (bookworm), this problem has been fixed in
    version 1.14.10-1~deb12u1. To address the vulnerability, flatpak uses a
    new feature provided in bubblewrap and provided in version
    0.8.0-2+deb12u1 along with this update.

    We recommend that you upgrade your flatpak packages.

    For the detailed security status of flatpak please refer to its security tracker page at:
    https://security-tracker.debian.org/tracker/flatpak

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAma9F2xfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0RINg/+OTenWEWdoatoO7F+184SOoVMYmmJTP2xtvuE8XC6S6NAcrYzjRQD1nyy xJK1IFmNjJrTf4HhfFTq2raOy60T6KRa0y71R1QS4+JOwNjdtr+zzDxdybXzg06T SOBKaLmped3PY4djFxoYnl9wEDLM+QAQuTWvnZugim4frEErmtlulwHRDA/qhWKT mzFiJgSWB7EJL61ddh2YVexru0b5rD6gyYcD7JoulbFjsOwvKyJhI4j1uuOrbNoj 7aArjlu9D3KymGQgCc5gg8yVp5Gt/ZFYsmFJ5BdAl5a8LmTBM4mMTDIsK39mPoLo waxpP0bJIfCxkNB+YOyJRPdj4mtT44nwDcG/LyM+M+f+R0HUr4Apftloheb72A0q XUS2tRrBEs0CzToeuwkIoo2XLQt7/vQ4HFMU47gtk6ZDKqIk7hWD0zcny8x3wL+p /Syd2xOA/KEmbLWFRDzoVVxpmLdkbqGJn+5p5FObMjOPNOFKyMs0Q7HukwKbyPGn YRhg1lcmOn30MWVFol2Z1Ex74IB//Wu/az7YZ4UIId1Y734NUVXEoTLvXGKV8Hnx 9m/0imWcz51T5DLqCv7MUX1i9V2s2R3Hj8GqQfVQTA39IH4GEmpZMR33XH/jvCDu p1GDW2KzIzObmLu+Kjkeg3NzRl/pKdDFiJncdNVG0PPhEn2hUY0=
    =hd0W
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)