CVE-2020-13753
Published on: 07/14/2020 12:00:00 AM UTC
Last Modified on: 01/28/2023 01:10:00 AM UTC
Certain versions of Ubuntu Linux from Canonical contain the following vulnerability:
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.
- CVE-2020-13753 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 10 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.5 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[security-announce] openSUSE-SU-2020:1064-1: important: Security update | lists.opensuse.org text/html |
![]() |
WebKitGTK+: Multiple vulnerabilities (GLSA 202007-11) — Gentoo security | security.gentoo.org text/html |
![]() |
[SECURITY] Fedora 31 Update: webkit2gtk3-2.28.3-1.fc31 - package-announce - Fedora Mailing-Lists | Vendor Advisory lists.fedoraproject.org text/html |
![]() |
Debian -- Security Information -- DSA-4724-1 webkit2gtk | Vendor Advisory www.debian.org Depreciated Link text/html |
![]() |
oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2020-0006 | Mailing List Third Party Advisory www.openwall.com text/html |
![]() |
Changeset 262368 – WebKit | Patch Vendor Advisory trac.webkit.org text/html |
![]() |
USN-4422-1: WebKitGTK+ vulnerabilities | Ubuntu security notices | Ubuntu | usn.ubuntu.com text/html |
![]() |
Related QID Numbers
- 501292 Alpine Linux Security Update for webkit2gtk
- 501707 Alpine Linux Security Update for webkit2gtk
- 690504 Free Berkeley Software Distribution (FreeBSD) Security Update for webkit2-gtk3 (efd03116-c2a9-11ea-82bc-b42e99a1b9c3)
- 751623 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0142-1)
- 751646 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0183-1)
- 751648 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0182-1)
- 751659 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-1)
- 751755 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-2)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
Operating System | Canonical | Ubuntu Linux | 20.04 | All | All | All |
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Operating System | Fedoraproject | Fedora | 31 | All | All | All |
Operating System | Fedoraproject | Fedora | 31 | All | All | All |
Operating System | Opensuse | Leap | 15.1 | All | All | All |
Application | Webkitgtk | Webkitgtk | All | All | All | All |
Application | Webkitgtk | Webkitgtk | All | All | All | All |
Application | Wpewebkit | Wpe Webkit | All | All | All | All |
Application | Wpewebkit | Wpe Webkit | All | All | All | All |
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*:
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*:
- cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*:
- cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*:
- cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*:
- cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*:
- cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE