Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12439

Опубликовано: 01 мар. 2019
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.

Отчет

This flaw requires a local user account to exploit. Since local users without root privileges are not supported on Red Had CloudForms, or on Red Hat Ansible Tower, this vulnerability is rated Low severity on these products. Future updates may address this vulnerability.

Меры по смягчению последствий

The default setting of fs.protected_symlinks = 1 prevents any Confidentiality or Integrity impact from exploiting this vulnerability, reducing its rating to Low severity (4.7/CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Tower 3bubblewrapAffected
Red Hat Enterprise Linux 8bubblewrapAffected
CloudForms Management Engine 5.10ansible-runnerFixedRHSA-2019:183324.07.2019
CloudForms Management Engine 5.10ansible-towerFixedRHSA-2019:183324.07.2019
CloudForms Management Engine 5.10bubblewrapFixedRHSA-2019:183324.07.2019
CloudForms Management Engine 5.10cfmeFixedRHSA-2019:183324.07.2019
CloudForms Management Engine 5.10cfme-amazon-smartstateFixedRHSA-2019:183324.07.2019
CloudForms Management Engine 5.10cfme-applianceFixedRHSA-2019:183324.07.2019
CloudForms Management Engine 5.10cfme-gemsetFixedRHSA-2019:183324.07.2019
CloudForms Management Engine 5.10ovirt-ansible-hosted-engine-setupFixedRHSA-2019:183324.07.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1695963bubblewrap: temporary directory misuse as mount point

EPSS

Процентиль: 35%
0.00143
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 6 лет назад

bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.

CVSS3: 7.4
nvd
больше 6 лет назад

bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.

CVSS3: 7.8
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 7.4
debian
больше 6 лет назад

bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories ...

suse-cvrf
около 6 лет назад

Security update for bubblewrap

EPSS

Процентиль: 35%
0.00143
Низкий

7 High

CVSS3