CVE-2020-13753

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-13753
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13753.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13753
Downstream
Related
Published
2020-07-14T14:15:17Z
Modified
2025-08-09T19:01:27Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONENEWUSER and the TIOCSTI ioctl. CLONENEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.

References

Affected packages