diff options
-rw-r--r-- | RELNOTES | 3 | ||||
-rw-r--r-- | etc/disable-common.inc | 12 |
2 files changed, 12 insertions, 3 deletions
@@ -1,8 +1,9 @@ | |||
1 | firejail (0.9.38.1) baseline; urgency=low | 1 | firejail (0.9.38.1) baseline; urgency=low |
2 | * testing in progress, it will be released as 0.9.38.2 | 2 | * testing in progress, it will be released as 0.9.38.2 |
3 | * security: --whitelist deleted files, submitted by Vasya Novikov | ||
3 | * security: disable x32 ABI, submitted by Jann Horn | 4 | * security: disable x32 ABI, submitted by Jann Horn |
4 | * security: tighten --chroot, submitted by Jann Horn | 5 | * security: tighten --chroot, submitted by Jann Horn |
5 | * security: --whitelist deleted files, submitted by Vasya Novikov | 6 | * security: terminal sandbox escape, submitted by Stephan Sokolow |
6 | -- netblue30 <netblue30@yahoo.com> Fri, 12 Aug 2016 10:00:00 -0500 | 7 | -- netblue30 <netblue30@yahoo.com> Fri, 12 Aug 2016 10:00:00 -0500 |
7 | 8 | ||
8 | firejail (0.9.38) baseline; urgency=low | 9 | firejail (0.9.38) baseline; urgency=low |
diff --git a/etc/disable-common.inc b/etc/disable-common.inc index 46dd04bcd..9f7274dc8 100644 --- a/etc/disable-common.inc +++ b/etc/disable-common.inc | |||
@@ -125,10 +125,18 @@ read-only ${HOME}/.xscreensaver | |||
125 | # The user ~/bin directory can override commands such as ls | 125 | # The user ~/bin directory can override commands such as ls |
126 | read-only ${HOME}/bin | 126 | read-only ${HOME}/bin |
127 | 127 | ||
128 | # disable terminals running as server | 128 | # disable terminals running as server resulting in sandbox escape |
129 | blacklist ${PATH}/lxterminal | 129 | blacklist ${PATH}/lxterminal |
130 | blacklist ${PATH}/gnome-terminal | 130 | blacklist ${PATH}/gnome-terminal |
131 | blacklist ${PATH}/gnome-terminal.wrapper | 131 | blacklist ${PATH}/gnome-terminal.wrapper |
132 | blacklist ${PATH}/xfce4-terminal | 132 | blacklist ${PATH}/xfce4-terminal |
133 | blacklist ${PATH}/xfce4-terminal.wrapper | 133 | blacklist ${PATH}/xfce4-terminal.wrapper |
134 | blacklist ${PATH}/konsole | 134 | blacklist ${PATH}/mate-terminal |
135 | blacklist ${PATH}/mate-terminal.wrapper | ||
136 | blacklist ${PATH}/lilyterm | ||
137 | blacklist ${PATH}/pantheon-terminal | ||
138 | blacklist ${PATH}/roxterm | ||
139 | blacklist ${PATH}/roxterm-config | ||
140 | blacklist ${PATH}/terminix | ||
141 | blacklist ${PATH}/urxvtc | ||
142 | blacklist ${PATH}/urxvtcd | ||