CVE-2019-12499

    Dashboard / Vulnerabilities / CVE-2019-12499

    CVE-2019-12499

    Published: 31 May 2019Last Modified: 8 Jul 2026

    Summary:

    Details: Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit code inside a firejail sandbox and having the sandbox terminated. To succeed, certain conditions need to be fulfilled: The jail (with the exploit code inside) needs to be started as root, and it also needs to be terminated as root from the host (either by stopping it ungracefully (e.g., SIGKILL), or by using the --shutdown control command). This is similar to CVE-2019-5736.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    0.9.60-rc1
    0.9.58.2
    0.9.58
    0.9.58-rc1
    0.9.56
    0.9.56-rc1
    0.9.54
    0.9.54-rc2
    0.9.54-rc1
    0.9.52
    0.9.50-rc1
    0.9.48
    0.9.46-rc1
    0.9.44
    0.9.44-rc1
    0.9.42
    0.9.42-rc2
    0.9.38
    0.9.42-rc1
    0.9.40
    0.9.40-rc1
    0.9.38-rc1
    0.9.36
    0.9.36-rc1
    0.9.34
    0.9.34-rc1
    0.9.32
    0.9.32-rc1
    0.9.30
    0.9.30-rc1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High