cvedb.io
CVE-2018-6560
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2018-02-02T14:29:01.637 · Last modified 2026-06-17T02:02:01.703

Summary

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

Affected products

flatpak — flatpak

Does this affect you?

Add your gear to cvedb and we'll alert you only when flatpak ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.