Описание
Security update for bubblewrap
This update for bubblewrap to version 0.3.3 fixes the following issue:
Security issue fixed:
- CVE-2019-12439: Fixed a temporary directory misuse as mount point which could have allowed local user to prevent others from running bubblewrap.
Список пакетов
openSUSE Leap 15.1
bubblewrap-0.3.3-lp151.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2019:1535-1
- SUSE Security Ratings
- SUSE Bug 1136958
- SUSE CVE CVE-2019-12439 page
Описание
bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
Затронутые продукты
openSUSE Leap 15.1:bubblewrap-0.3.3-lp151.2.3.1
Ссылки
- CVE-2019-12439
- SUSE Bug 1136958