bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDGRUNTIMEDIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
[ { "id": "CVE-2019-12439-0814091c", "source": "https://github.com/containers/bubblewrap/commit/efc89e3b939b4bde42c10f065f6b7b02958ed50e", "signature_type": "Function", "digest": { "function_hash": "163138480516088060973123991537078844772", "length": 10855.0 }, "signature_version": "v1", "target": { "function": "main", "file": "bubblewrap.c" }, "deprecated": false }, { "id": "CVE-2019-12439-776902b2", "source": "https://github.com/containers/bubblewrap/commit/efc89e3b939b4bde42c10f065f6b7b02958ed50e", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "283179917051261630896667241276398686681", "156835895842063204426592657645357554064", "111535406409657270217145089257984278610", "113780544056907384740793531340704701702", "137732832239418312694642623703253456288", "124682311427914636375661048704732540145", "170496425584988668139365274346094921978", "172801237529990720369066095369241666423", "217023891360866399185816632672554550288", "174097707395110539665399886529019003634", "297473727901272319493434324414327787637", "276028077305428303997258195433187177581", "246543047571715569257987064028953445438", "74241571744933200156231765948065868072", "229410691217233813825979016078530512815", "42059878739010556504832711124538710956", "44532719681789361639233861930549587264", "198386674756433031549864431927558446003" ] }, "signature_version": "v1", "target": { "file": "bubblewrap.c" }, "deprecated": false } ]