CVE-2019-12499
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit code inside a firejail sandbox and having the sandbox terminated. To succeed, certain conditions need to be fulfilled: The jail (with the exploit code inside) needs to be started as root, and it also needs to be terminated as root from the host (either by stopping it ungracefully (e.g., SIGKILL), or by using the --shutdown control command). This is similar to CVE-2019-5736.
Firejail anterior a la versión 0.9.60 permite el truncado (redimensionar a longitud 0) del binario de firejail en el host ejecutando el código de operación dentro de sandbox de firejail y habiendo terminado el sandbox. Para tener éxtio, ciertas condiciones deben cumplirse: La jaula (con el código de explotación en el interior) debe iniciarse como root, y también necesita ser terminada como root desde el host (ya sea deteniéndola sin contemplaciones (por ejemplo, SIGKILL), o usando el comando de control--shutdown). Todo lo anterior es igual a lo indicado en CVE-2019-5736.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-05-31 CVE Reserved
- 2019-05-31 CVE Published
- 2024-08-04 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/netblue30/firejail/issues/2401 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Firejail Project Search vendor "Firejail Project" | Firejail Search vendor "Firejail Project" for product "Firejail" | < 0.9.60 Search vendor "Firejail Project" for product "Firejail" and version " < 0.9.60" | - |
Affected
|