CVE-2019-12439

Published

Severity

CVSS v3:
7.8 HIGH
CVSS v2:
4.6 MEDIUM

Description

bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:projectatomic:bubblewrap:*:*:*:*:*:*:*:*n/a0.3.3*

External Links