CVE-2019-12499 affects Firejail versions prior to 0.9.60, allowing a malicious actor to truncate the Firejail binary on the host system. This high-severity vulnerability (CVSS 8.1) requires specific conditions for exploitation: the sandbox must be started as root and then terminated as root, either ungracefully or via the --shutdown command. While the potential impact is significant, there is currently no evidence of active exploitation, public exploit code, or notable community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.60CPE matchmatch criteria | cpe:2.3:a:firejail_project:firejail:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.