GLSA Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Jun 15, 2020 9:26 pm Post subject: [ GLSA 202006-18 ] Bubblewrap |
|
|
Gentoo Linux Security Advisory
Title: Bubblewrap: Arbitrary code execution (GLSA 202006-18)
Severity: normal
Exploitable: local
Date: 2020-06-15
Bug(s): #686114
ID: 202006-18
Synopsis
Bubblewrap misuses temporary directories allowing local code
execution.
Background
Bubblewrap is an unprivileged sandboxing tool namespaces-powered
chroot-like solution.
Affected Packages
Package: sys-apps/bubblewrap
Vulnerable: < 0.4.1
Unaffected: >= 0.4.1
Architectures: All supported architectures
Description
Bubblewrap misuses temporary directories in /tmp as a mount point.
Impact
This flaw may allow possible execution of code or prevention of running
Bubblewrap.
Workaround
There is no known workaround at this time.
Resolution
All Bubblewrap users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=sys-apps/bubblewrap-0.4.1"
|
References
CVE-2019-12439 |
|