Lucene search

K
redhatcveRedhat.comRH:CVE-2019-10063
HistoryOct 09, 2019 - 11:42 p.m.

CVE-2019-10063

2019-10-0923:42:02
redhat.com
access.redhat.com
13

0.008 Low

EPSS

Percentile

81.6%

An incomplete fix for CVE-2017-5226 was found in flatpak. A sandbox bypass flaw was found in the way bubblewrap, which is used for sandboxing flatpak applications handled the TIOCSTI ioctl. A malicious flatpak application could use this flaw to inject commands into the controlled terminal of the host after the flatpak applications exits. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.