CVE-2020-13753: Input Validation
Last updated 24 July 2024
Other sources
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONENEWUSER and the TIOCSTI ioctl. CLONENEWUSER could potentially be used to confuse xdg- desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal’s input buffer, similar to CVE-2017-5226. Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before 2.28.3.
— Red Hat
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONENEWUSER and the TIOCSTI ioctl. CLONENEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-13753?
CVE-2020-13753 is a vulnerability in the bubblewrap sandbox of WebKitGTK and WPE WebKit that allows unauthorized access outside the sandbox.
How severe is CVE-2020-13753?
CVE-2020-13753 has a severity value of 10, indicating a critical vulnerability.
Which software versions are affected by CVE-2020-13753?
CVE-2020-13753 affects WebKitGTK versions 2.28.3 and earlier, and WPE WebKit versions 2.28.3 and earlier.
How can I fix CVE-2020-13753?
To fix CVE-2020-13753, update WebKitGTK to version 2.28.3 or later, and WPE WebKit to version 2.28.3 or later.
Where can I find more information about CVE-2020-13753?
You can find more information about CVE-2020-13753 on the following references: [http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00074.html](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00074.html), [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GER2ATKZXDHM7FFYJH67ZPNZZX5VOUVM/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GER2ATKZXDHM7FFYJH67ZPNZZX5VOUVM/), [https://security.gentoo.org/glsa/202007-11](https://security.gentoo.org/glsa/202007-11)