Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Arch Linux: 2019-05-06 High Severity: Nautilus Sandbox Escape

Archlinux Large Esm H500
The package nautilus before version 3.32.1-1 is vulnerable to sandbox escape.
Arch Linux Security Advisory ASA-201905-3
========================================
Severity: High
Date    : 2019-05-06
CVE-ID  : CVE-2019-11461
Package : nautilus
Type    : sandbox escape
Remote  : No
Link    : https://security.archlinux.org/AVG-956

Summary
======
The package nautilus before version 3.32.1-1 is vulnerable to sandbox
escape.

Resolution
=========
Upgrade to 3.32.1-1.

# pacman -Syu "nautilus>=3.32.1-1"

The problem has been fixed upstream in version 3.32.1.

Workaround
=========
None.

Description
==========
An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32
prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap
sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push
characters into the input buffer of the thumbnailer's controlling
terminal, allowing an attacker to escape the sandbox if the thumbnailer
has a controlling terminal. This is due to improper filtering of the
TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.

Impact
=====
A local attacker is able to escape the sandbox.

References
=========


https://security.archlinux.org/CVE-2019-11461

Related News

Your message here