6.9
CVSSv2

CVE-2016-8659

Published: 13/02/2017 Updated: 16/02/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Bubblewrap prior to 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bubblewrap project bubblewrap

Vendor Advisories

Debian Bug report logs - #840605 bubblewrap: CVE-2016-8659 Package: src:bubblewrap; Maintainer for src:bubblewrap is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 13 Oct 2016 07:42:01 UTC Severity: grave Tags: security, upstr ...