aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--RELNOTES3
-rw-r--r--etc/disable-common.inc12
2 files changed, 12 insertions, 3 deletions
diff --git a/RELNOTES b/RELNOTES
index 015bb2137..da53398de 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -1,8 +1,9 @@
1firejail (0.9.38.1) baseline; urgency=low 1firejail (0.9.38.1) baseline; urgency=low
2 * testing in progress, it will be released as 0.9.38.2 2 * testing in progress, it will be released as 0.9.38.2
3 * security: --whitelist deleted files, submitted by Vasya Novikov
3 * security: disable x32 ABI, submitted by Jann Horn 4 * security: disable x32 ABI, submitted by Jann Horn
4 * security: tighten --chroot, submitted by Jann Horn 5 * security: tighten --chroot, submitted by Jann Horn
5 * security: --whitelist deleted files, submitted by Vasya Novikov 6 * security: terminal sandbox escape, submitted by Stephan Sokolow
6 -- netblue30 <netblue30@yahoo.com> Fri, 12 Aug 2016 10:00:00 -0500 7 -- netblue30 <netblue30@yahoo.com> Fri, 12 Aug 2016 10:00:00 -0500
7 8
8firejail (0.9.38) baseline; urgency=low 9firejail (0.9.38) baseline; urgency=low
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 46dd04bcd..9f7274dc8 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -125,10 +125,18 @@ read-only ${HOME}/.xscreensaver
125# The user ~/bin directory can override commands such as ls 125# The user ~/bin directory can override commands such as ls
126read-only ${HOME}/bin 126read-only ${HOME}/bin
127 127
128# disable terminals running as server 128# disable terminals running as server resulting in sandbox escape
129blacklist ${PATH}/lxterminal 129blacklist ${PATH}/lxterminal
130blacklist ${PATH}/gnome-terminal 130blacklist ${PATH}/gnome-terminal
131blacklist ${PATH}/gnome-terminal.wrapper 131blacklist ${PATH}/gnome-terminal.wrapper
132blacklist ${PATH}/xfce4-terminal 132blacklist ${PATH}/xfce4-terminal
133blacklist ${PATH}/xfce4-terminal.wrapper 133blacklist ${PATH}/xfce4-terminal.wrapper
134blacklist ${PATH}/konsole 134blacklist ${PATH}/mate-terminal
135blacklist ${PATH}/mate-terminal.wrapper
136blacklist ${PATH}/lilyterm
137blacklist ${PATH}/pantheon-terminal
138blacklist ${PATH}/roxterm
139blacklist ${PATH}/roxterm-config
140blacklist ${PATH}/terminix
141blacklist ${PATH}/urxvtc
142blacklist ${PATH}/urxvtcd