-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.0463
                         firejail security update
                             10 February 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           firejail
Publisher:         Debian
Operating System:  Debian GNU/Linux
                   Linux variants
Impact/Access:     Root Compromise      -- Existing Account
                   Increased Privileges -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2021-26910  

Original Bulletin: 
   http://www.debian.org/security/2021/dsa-4849

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running firejail check for an updated version of the software for 
         their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-4849-1                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
February 09, 2021                     https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : firejail
CVE ID         : CVE-2021-26910

Roman Fiedler discovered a vulnerability in the OverlayFS code in
firejail, a sandbox program to restrict the running environment of
untrusted applications, which could result in root privilege escalation.
This update disables OverlayFS support in firejail.

For the stable distribution (buster), this problem has been fixed in
version 0.9.58.2-2+deb10u2.

We recommend that you upgrade your firejail packages.

For the detailed security status of firejail please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/firejail

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmAi+oVfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0TfcA/+Oql0UYg91bBhISV37airwVjjdiLubX6bBpd4F3T12TPDuPBMxofY+61o
M10BBbW8w7MQaQ+uePFT+rL8I3UNU6j3BtvdU8L11FIvkIFIYMKC5VkqThNsJaNK
r/LGxIQbxudY2yr7DFOao2pdF5KoorcTcK8Vw/ULiRIL1/jtfzM7tz6RZjVysKlC
tNfY7GGOMmHTFyxPkU6sAlAS9scUZuQEJHIAJuzbLHMudoFf5jE2+HbnhAuiYKYh
q34ewtuNSda2H4hMNC6U76StdKmWvqjVuPyt9kQ1HVF+gbcaNRz7XL0rC1YEcnpo
d3mGZem1Pa5TcFzjaH8OKfqTsNKU+gC5JbRt/JmQho0IS8BPdZxOiHWWplawjj/k
K1VfBIWNJBf2Z9guoTqBkfLB5B1nreO3opVhgveft9NiH5ydeFa1z92utLQPN8fN
Mr7quGK88F9EGlORHdCXoqp4WTAai5wwdUkjY+y+Zt1Cr7wTsdTSvcWNKQQP8EvT
fhFTvU/57f3/jqE2N/FStDdcJNt95Q81qiuM7Ot4c9UQBuSGhcUo1+eoCArj1niv
MqeHc+bMv/Wxrg6LGsAEnDTgQHVBul+hROFBqlUExsQSLwq5o0jjUGBT8V3ZkXs6
JU69tVRsNU6c2+BHjg8zclURqQ3mLTW0BCReKK5JqbL8eo1G2lA=
=+BOy
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYCNuj+NLKJtyKPYoAQgQUQ/9ETOhFjRSAWtwKMVoWl7X0bLoh23PREVG
0607LNg7zUp1Xfx5lipLrt8YV4+m6VojYv26dgrnT3LBuwxrSIVmuIejvAFXDi1T
Q405ZUigy8/fbrZnDg2YqzADQYsPlVZBrqWfo4h8jYCe66zFUnDS9+oxkGFdzWbe
WeqVYd488ALwpmhuG5sB/xVXM3L2xE+GIbL4o9ei0iTabCZ7gEESjOGVZdK3Qgr3
oCEP6Ju3Sgn1V33KKv/666KpOe3zANnjcJye0wMu4FaRI2ca+nbmDRWOQaNj7cia
itRtIkymqgYLyIA+JISaOPDOeJKTKDLIMjN4xrTzEDBmmhHMENu2LBQi4hZm+No7
TbYwMXZpIqJFLfzAXWvO3FJbcgYodVWvLFjb/anMztPa/eLs4PJbEWIseJpI3fWI
xdm2ARYMJeNAaPnK3uUXOt8nbWUp42jREDAbxWOMsYjHKnaI91hgrHUFew7RV/Bl
WReRABXecZ3IV8lzcFnFcM33pQ9Xp1I4aOUd7nlo17+KPsxpN0J4UKlL0/b44h7K
pvMEyrQmNOPoNOBFNMuZXEFMTWMODczmuXOKh3h/QTFjhheluP/ZBSX/vPnFA38H
9FwjflDwvpZvFT0qeykBMIRYCckBaAcI3EZRsrzkm0mKI5RRovk3FJ+qzGEf7iDO
tw7DJBHlxLg=
=Fyer
-----END PGP SIGNATURE-----