CVE-2019-12439 describes a vulnerability in Bubblewrap (projectatomic bubblewrap) versions prior to 0.3.3, where bubblewrap.c incorrectly uses /tmp as a mount point for temporary directories. This flaw, under specific XDG_RUNTIME_DIR configurations, allows a local attacker to disrupt Bubblewrap execution for other users or potentially execute arbitrary code. With a CVSS score of 7.8 (HIGH), the vulnerability has a low attack complexity and requires local user privileges, but can lead to high impacts on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.3CPE matchmatch criteria | cpe:2.3:a:projectatomic:bubblewrap:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-12439
Aug 11, 2020bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR) a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.
May 14, 2019bubblewrap: temporary directory misuse as mount point
Mar 1, 2019