LiveActive security incident?Get immediate response
CVE Record

CVE-2017-9780: In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with...

In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the "system helper" component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysis

Security readout for executives and security teams

Flatpak before 0.8.7 could install malicious third-party apps with unsafe file permissions. If an organization allowed untrusted Flatpak repositories, a local user could potentially run privileged files or modify writable locations. The worst case named in the sources is setuid root files when installed through the system helper. Exposure is most likely on Linux systems running Flatpak before 0.8.7, especially where third-party Flatpak repositories are configured or users can install apps from them. Treat as a targeted local privilege risk, not an internet-scale emergency. Prioritize shared Linux workstations, developer machines, and systems where users install Flatpak apps from third-party repositories. Mitigation focus: Upgrade Flatpak to 0.8.7 or a vendor-supported fixed package.; Apply the Debian security update where Debian packages are used.; Remove or restrict untrusted third-party Flatpak repositories..

Prepared

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-9780 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.