CVE-2019-12439 PUBLISHED

bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.

EPSS 0.15% · 35.4th percentile

Risk Scores

EPSS Score
0.15%
35.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSbubblewrap0, 0.2.0-1, 0.2.0-2

Timeline

References

Open in Interactive Console →