CVE-2020-13753 log
Source |
|
Severity | High |
Remote | No |
Type | Sandbox escape |
Description | The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg- desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal’s input buffer, similar to CVE-2017-5226. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1203 | webkit2gtk | 2.28.2-2 | 2.28.3-1 | Critical | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
14 Jul 2020 | ASA-202007-1 | AVG-1203 | webkit2gtk | Critical | multiple issues |
References |
---|
https://webkitgtk.org/security/WSA-2020-0006.html#CVE-2020-13753 |