Package: xdg-dbus-proxy Version: 0.1.0-1 Severity: grave Tags: security Justification: user security hole X-Debbugs-Cc: Debian Security Team <[email protected]>
https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq >An incorrect implementation of message filtering in xdg-dbus-proxy >versions before 0.1.9 allows an attacker to bypass the intended message >filtering on the D-Bus session bus by setting a reply serial number on >non-reply messages. > >xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, >but it is released as a separate project and is sometimes used by other >app frameworks such as Firejail. > >Impact: > >A malicious or compromised Flatpak app could achieve arbitrary code >execution outside its sandbox. > >If other app frameworks rely on xdg-dbus-proxy in the same way that >Flatpak does, then they will have an equivalent vulnerability until >xdg-dbus-proxy is updated. > >Workarounds: > >Avoid running untrusted Flatpak apps. > >Avoid running untrusted apps via other frameworks that use xdg-dbus-proxy.

