CVE-2019-12439: Input Validation
Published Apr 4, 2019
·Updated
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
Affected Software
2 affected componentsFixes available
redhat/bubblewrap<0.3.3
0.3.3
projectatomic bubblewrap<0.3.3
Remediation
Event History
Apr 4, 2019
Data Sourced
via Red Hat·12:11 AM
DescriptionSeverityAffected Software
May 29, 2019
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
DescriptionSeverity