{"id":"CVE-2017-5206","details":"Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument.","modified":"2026-08-18T09:28:16.085384Z","published":"2017-03-23T16:59:00.417Z","related":["openSUSE-SU-2024:10759-1"],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97120"},{"type":"ADVISORY","url":"https://blog.lizzie.io/linux-containers-in-500-loc.html#fn.51"},{"type":"ADVISORY","url":"https://firejail.wordpress.com/download-2/release-notes/"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2017/01/07/5"},{"type":"FIX","url":"https://github.com/netblue30/firejail/commit/6b8dba29d73257311564ee7f27b9b14758cc693e"},{"type":"FIX","url":"https://security.gentoo.org/glsa/201701-62"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/netblue30/firejail","events":[{"introduced":"0"},{"fixed":"e0422ca2be6482f375400562b68e9d72d739964b"}],"database_specific":{"cpe":"cpe:2.3:a:firejail_project:firejail:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.9.44.4"}],"source":"CPE_FIELD"}}],"versions":["0.9.44.2","0.9.44","0.9.44-rc1","0.9.42","0.9.42-rc2","0.9.38","0.9.42-rc1","disable-globalcfg","0.9.40","0.9.40-rc1","0.9.38-rc1","0.9.36","0.9.36-rc1","0.9.34","0.9.34-rc1","0.9.32","0.9.32-rc1","0.9.30","0.9.30-rc1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5206.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}