bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp...
Vulnerability Description
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-12439
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/projectatomic/bubblewrap/issues/304
- https://github.com/projectatomic/bubblewrap/commit/efc89e3b939b4bde42c10f065f6b7b02958ed50e
- https://bugzilla.redhat.com/show_bug.cgi?id=1695963
- https://github.com/projectatomic/bubblewrap/releases/tag/v0.3.3
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00015.html
- https://access.redhat.com/errata/RHSA-2019:1833
- https://security.gentoo.org/glsa/202006-18
Affected Vendor
projectatomic
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.