4.6
CVSSv2

CVE-2019-12439

Published: 29/05/2019 Updated: 15/06/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

bubblewrap.c in Bubblewrap prior to 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

projectatomic bubblewrap

Vendor Advisories

Synopsis Low: CloudForms 477 security, bug fix and enhancement update Type/Severity Security Advisory: Low Topic An update is now available for CloudForms Management Engine 510Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) ...
Debian Bug report logs - #923557 bubblewrap: CVE-2019-12439: insecure use of /tmp Package: bubblewrap; Maintainer for bubblewrap is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for bubblewrap is src:bubblewrap (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@jwilknet> Date: Fr ...