vendor:
Firejail
by:
Sebastian Krahmer
7,2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Firejail
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
firejail local root exploit (host to host)
This exploit uses ld.so.preload technique to tamper with /etc/ld.so.preload and launch a rootshell. It is a shared library and a running executable at the same time. It was tested with the latest commit 699ab75654ad5ab7b48b067a2679c544cc8725f6.
Mitigation:
Ensure that the sandboxing is done correctly and that the attack surface is not too broad.