10
CVSSv3

CVE-2020-13753

Published: 14/07/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The bubblewrap sandbox of WebKitGTK and WPE WebKit, before 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wpewebkit wpe webkit

webkitgtk webkitgtk

fedoraproject fedora 31

debian debian linux 10.0

canonical ubuntu linux 18.04

canonical ubuntu linux 19.10

canonical ubuntu linux 20.04

opensuse leap 15.1

Vendor Advisories

The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2020-9802 Samuel Gross discovered that processing maliciously crafted web content may lead to arbitrary code execution CVE-2020-9803 Wen Xu discovered that processing maliciously crafted web content may lead to arbitrary code execution CVE-2020-9 ...
Severity Unknown Remote Unknown Type Unknown Description AVG-1203 webkit2gtk 2282-2 2283-1 Unknown Fixed ...