CVE Database
/

CVE-2019-12499

Back to search

CVE-2019-12499

Published: May 31, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit code inside a firejail sandbox and having the sandbox terminated. To succeed, certain conditions need to be fulfilled: The jail (with the exploit code inside) needs to be started as root, and it also needs to be terminated as root from the host (either by stopping it ungracefully (e.g., SIGKILL), or by using the --shutdown control command). This is similar to CVE-2019-5736.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2020-0fb484d7f7
vendor-advisory
x_refsource_FEDORA
FEDORA-2020-7f6e0e6e00
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now