diff options
-rw-r--r-- | RELNOTES | 4 | ||||
-rw-r--r-- | etc/disable-common.inc | 4 |
2 files changed, 5 insertions, 3 deletions
@@ -1,4 +1,8 @@ | |||
1 | firejail (0.9.42~rc2) baseline; urgency=low | 1 | firejail (0.9.42~rc2) baseline; urgency=low |
2 | * security: --whitelist deleted files, submitted by Vasya Novikov | ||
3 | * security: disable x32 ABI, submitted by Jann Horn | ||
4 | * security: tighten --chroot, submitted by Jann Horn | ||
5 | * security: terminal sandbox escape, submitted by Stephan Sokolow | ||
2 | * deprecated --user option, please use "sudo -u username firejail" instead | 6 | * deprecated --user option, please use "sudo -u username firejail" instead |
3 | * --read-write option rework | 7 | * --read-write option rework |
4 | * allow symlinks in home directory for --whitelist option | 8 | * allow symlinks in home directory for --whitelist option |
diff --git a/etc/disable-common.inc b/etc/disable-common.inc index ed6ee315b..c4169db8a 100644 --- a/etc/disable-common.inc +++ b/etc/disable-common.inc | |||
@@ -155,7 +155,7 @@ blacklist /usr/local/sbin | |||
155 | # prevent lxterminal connecting to an existing lxterminal session | 155 | # prevent lxterminal connecting to an existing lxterminal session |
156 | blacklist /tmp/.lxterminal-socket* | 156 | blacklist /tmp/.lxterminal-socket* |
157 | 157 | ||
158 | # disable terminals running as server | 158 | # disable terminals running as server resulting in sandbox escape |
159 | blacklist ${PATH}/gnome-terminal | 159 | blacklist ${PATH}/gnome-terminal |
160 | blacklist ${PATH}/gnome-terminal.wrapper | 160 | blacklist ${PATH}/gnome-terminal.wrapper |
161 | blacklist ${PATH}/xfce4-terminal | 161 | blacklist ${PATH}/xfce4-terminal |
@@ -169,5 +169,3 @@ blacklist ${PATH}/roxterm-config | |||
169 | blacklist ${PATH}/terminix | 169 | blacklist ${PATH}/terminix |
170 | blacklist ${PATH}/urxvtc | 170 | blacklist ${PATH}/urxvtc |
171 | blacklist ${PATH}/urxvtcd | 171 | blacklist ${PATH}/urxvtcd |
172 | blacklist ${PATH}/konsole | ||
173 | blacklist ${PATH}/yakuake | ||