Files
flatpak/tests
Simon McVittie de68092f7f run: Prevent TIOCLINUX ioctl, the same as TIOCSTI
The TIOCLINUX ioctl is only available on Linux virtual consoles such as
/dev/tty1. It has several Linux-specific functions, one of which is a
copy/paste operation which can be used for attacks similar to TIOCSTI.

This vulnerability does not affect typical graphical terminal emulators
such as xterm, gnome-terminal and Konsole, and Flatpak is primarily
designed to be run from a Wayland or X11 graphical environment, so this
is relatively unlikely to be a practical problem.

CVE-2023-28100, GHSA-7qpw-3vjv-xrqp

Resolves: https://github.com/flatpak/flatpak/security/advisories/GHSA-7qpw-3vjv-xrqp
Signed-off-by: Simon McVittie <smcv@debian.org>
2023-03-16 09:55:31 +00:00
..
2016-02-25 15:27:37 +01:00
2019-04-08 12:50:42 +00:00
2019-12-17 14:55:13 +01:00
2019-03-06 23:44:50 +00:00
2021-05-25 11:11:03 +02:00
2016-02-25 19:03:09 +01:00
2021-08-23 12:19:03 +02:00
2020-03-20 15:37:10 +01:00
2021-05-25 11:11:03 +02:00
2022-01-04 10:44:37 -08:00
2022-01-04 10:44:37 -08:00
2021-05-25 11:11:03 +02:00
2021-05-25 11:11:03 +02:00