Should I keep using the version of firejail available in my distro repos? Or should I download the .deb from the official site? #4666
-
Hi, Source: https://firejail.wordpress.com/download-2/ Is it acceptable from a security angle if I keep using 0.9.62? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 7 replies
-
If they didn't patched it, your firejail version is vulnerable to CVE-2021-26910, CVE-2020-17367 and In general it isn't a security problem to use old firejail version (as long as CVE get pacthed). However newer firejail versions have more/better profile and new hardening features (like dbus filtering in 0.9.64).
apt uses .deb too 😉. If you want a newer version, you should use the PPA. My recommendation: Use the backports version if you're on debian, the PPA if you're on ubuntu (and don't use ubuntu). |
Beta Was this translation helpful? Give feedback.
-
I am no longer using Ubuntu. I have installed EndeavourOS. $ firejail --version
firejail version 0.9.66 |
Beta Was this translation helpful? Give feedback.
If they didn't patched it, your firejail version is vulnerable to CVE-2021-26910, CVE-2020-17367 and
CVE-2020-17368. IDK what ubu has patched and what not but I really don't expect anything from ubuntu, especially LTS.
In general it isn't a security problem to use old firejail version (as long as CVE get pacthed). However newer firejail versions have more/better profile and new hardening features (like dbus filtering in 0.9.64).
apt uses .deb too 😉. If you want a newer version, you should use the PPA.
My recommendation: Use the backports version if you're on debian, the PPA if you're on ubunt…