Firejail through 0.9.62 does not honor the — end-of-options indicator after the –output option, which may lead to command injection.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17367
Reference (s):
- DEBIAN:DSA-4743
- URL: https://www.debian.org/security/2020/dsa-4743
- FEDORA:FEDORA-2020-45fc8559d5
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/W66IR5YT4KG464SKEMQN2NP2LGATGEGS/
- FEDORA:FEDORA-2020-80a6d7e7e0

