PT-2019-12797 · Project Bubblewrap+2 · Bubblewrap+2
Ret2Libc
·
Published
2019-05-29
·
Updated
2024-06-15
·
CVE-2019-12439
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bubblewrap versions prior to 0.3.3
Description
The issue arises from the misuse of temporary directories in /tmp as a mount point by bubblewrap.c in Bubblewrap. In specific configurations related to XDG RUNTIME DIR, a local attacker may exploit this flaw to prevent other users from executing bubblewrap or potentially execute code.
Recommendations
For versions prior to 0.3.3, update to version 0.3.3 or later to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Bubblewrap