PT-2019-12797 · Project Bubblewrap+2 · Bubblewrap+2
Ret2Libc
·
Publicado
2019-05-29
·
Atualizado
2024-06-15
·
CVE-2019-12439
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bubblewrap versions prior to 0.3.3
Description
The issue arises from the misuse of temporary directories in /tmp as a mount point by bubblewrap.c in Bubblewrap. In specific configurations related to XDG RUNTIME DIR, a local attacker may exploit this flaw to prevent other users from executing bubblewrap or potentially execute code.
Recommendations
For versions prior to 0.3.3, update to version 0.3.3 or later to resolve the issue.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Bubblewrap