CVE-2017-5226 Information
Feb 14, 2021
cve
Description
When executing a program via the bubblewrap sandbox the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal’s input buffer allowing an attacker to escape the sandbox.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Reference
http://www.openwall.com/lists/oss-security/2020/07/10/1 http://www.securityfocus.com/bid/97260 https://bugzilla.redhat.com/show_bug.cgi?id=1411811 https://github.com/projectatomic/bubblewrap/commit/d7fc532c42f0e9bf427923bab85433282b3e5117 https://github.com/projectatomic/bubblewrap/issues/142
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
10.0
Share on: