6.8
CVSSv2

CVE-2019-11460

Published: 22/04/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in GNOME gnome-desktop 3.26, 3.28, and 3.30 before 3.30.2.2, and 3.32 before 3.32.1.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an malicious user to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnome-desktop 3.28.0

gnome gnome-desktop 3.26.0

gnome gnome-desktop

Vendor Advisories

Debian Bug report logs - #928732 CVE-2019-11460 Package: src:gnome-desktop3; Maintainer for src:gnome-desktop3 is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 9 May 2019 20:39:01 UTC Severity: important Tags: fixed-upstream, sec ...
gnome-desktop could be made to escape the thumbnailer sandbox ...