Skip to content

Should I keep using the version of firejail available in my distro repos? Or should I download the .deb from the official site? #4666

Discussion options

You must be logged in to vote

Is it acceptable from a security angle if I keep using 0.9.62 ?

If they didn't patched it, your firejail version is vulnerable to CVE-2021-26910, CVE-2020-17367 and
CVE-2020-17368. IDK what ubu has patched and what not but I really don't expect anything from ubuntu, especially LTS.

In general it isn't a security problem to use old firejail version (as long as CVE get pacthed). However newer firejail versions have more/better profile and new hardening features (like dbus filtering in 0.9.64).

Or should I download a .deb ?

apt uses .deb too 😉. If you want a newer version, you should use the PPA.

My recommendation: Use the backports version if you're on debian, the PPA if you're on ubunt…

Replies: 2 comments 7 replies

Comment options

You must be logged in to vote
7 replies
@reinerh
Comment options

@firejailaddssecuirty
Comment options

@kmk3
Comment options

@rusty-snake
Comment options

@kmk3
Comment options

Answer selected by rusty-snake
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants