7
CVE-2016-8659
- EPSS 0.4%
- Veröffentlicht 13.02.2017 18:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bubblewrap Project ≫ Bubblewrap Version <= 0.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.315 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7 | 1 | 5.9 |
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
http://www.openwall.com/lists/oss-security/2016/10/12/5
http://www.openwall.com/lists/oss-security/2016/10/13/4
http://www.securityfocus.com/bid/93542
https://github.com/projectatomic/bubblewrap/issues/107