Описание
Security update for bubblewrap
This update for bubblewrap fixes the following issues:
Security issue fixed:
- CVE-2019-12439: Fixed insecure use of /tmp (bsc#1136958).
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15
bubblewrap-0.2.0-3.3.1
Ссылки
- Link for SUSE-SU-2019:1826-1
- E-Mail link for SUSE-SU-2019:1826-1
- SUSE Security Ratings
- SUSE Bug 1136958
- SUSE CVE CVE-2019-12439 page
Описание
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15:bubblewrap-0.2.0-3.3.1
Ссылки
- CVE-2019-12439
- SUSE Bug 1136958