CVE-2017-9780
Last modified
CVE-2017-9780 is a vulnerability of currently unknown severity. In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the "system helper" component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Flatpak | Flatpak | <= 0.8.6 |
| Debian | Debian Linux | 9.0 |
References
- http://www.debian.org/security/2017/dsa-3895Third Party Advisory
- http://www.securityfocus.com/bid/99346Third Party Advisory, VDB Entry
- https://bugs.debian.org/865413Issue Tracking, Patch, Third Party Advisory
- https://github.com/flatpak/flatpak/issues/845Issue Tracking, Patch, Third Party Advisory
- http://www.debian.org/security/2017/dsa-3895Third Party Advisory
- http://www.securityfocus.com/bid/99346Third Party Advisory, VDB Entry
- https://bugs.debian.org/865413Issue Tracking, Patch, Third Party Advisory
- https://github.com/flatpak/flatpak/issues/845Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9780?
How severe is CVE-2017-9780?
How do I fix CVE-2017-9780?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-9773Denial of Service was found in Horde_Image 2.x before 2.5.0 …
- CVE-2017-9774Remote Code Execution was found in Horde_Image 2.x before 2.…
- CVE-2017-9775Stack buffer overflow in GfxState.cc in pdftocairo in Popple…
- CVE-2017-9776Integer overflow leading to Heap buffer overflow in JBIG2Str…
- CVE-2017-9778GNU Debugger (GDB) 8.0 and earlier fails to detect a negativ…
- CVE-2017-9779OCaml compiler allows attackers to have unspecified impact v…
- CVE-2017-9781A cross site scripting (XSS) vulnerability exists in Check_M…
- CVE-2017-9782JasPer 2.0.12 allows remote attackers to cause a denial of s…
- CVE-2017-9783Cross-site scripting (XSS) vulnerability in ProjectSend (for…
- CVE-2017-9785Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dan…
- CVE-2017-9786Cross-site scripting (XSS) vulnerability in ProjectSend (for…
- CVE-2017-9787When using a Spring AOP functionality to secure Struts actio…
Are you affected by CVE-2017-9780?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
