Firejail through 0.9.62 mishandles shell metacharacters during use of the –output or –output-stderr option, which may lead to command injection.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17368
Reference (s):
- DEBIAN:DSA-4742
- URL: https://www.debian.org/security/2020/dsa-4742
- DEBIAN:DSA-4743
- URL: https://www.debian.org/security/2020/dsa-4743
- FEDORA:FEDORA-2020-45fc8559d5

