CVE-2019-11461
published 2019-04-22CVE-2019-11461: An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to…
PriorityP336high7.8CVSS 3.0
AVLACHPRLUINSCCHIHAH
EPSS
0.35%
27.5th percentile
An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nautilus | < nautilus 3.30.5-2 (bookworm) | nautilus 3.30.5-2 (bookworm) |
| gnome | nautilus | >= 0 < 3.30.5-2 | 3.30.5-2 |
| gnome | nautilus | >= 0 < 3.30.5-2 | 3.30.5-2 |
| gnome | nautilus | >= 0 < 3.30.5-2 | 3.30.5-2 |
| gnome | nautilus | >= 0 < 3.30.5-2 | 3.30.5-2 |
| gnome | nautilus | >= 3.30 < 3.30.6 | 3.30.6 |
| gnome | nautilus | >= 3.32 < 3.32.1 | 3.32.1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv9.0CRITICAL
vendor_debian9.0CRITICAL
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nautilus: sandbox security bypass
vendor_redhat·2019-04-13·CVSS 9.0
CVE-2019-11461 [CRITICAL] CWE-358 nautilus: sandbox security bypass
nautilus: sandbox security bypass
An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.
Package: nautilus (Red Hat Enterprise Linux 5) - Not affected
Package: nautilus (Red Hat Enterprise Linux 6) - Not affected
Package: nautilus (Red Hat Enterprise Linux 7) - Not affected
Package: nautilus (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2019-11461: nautilus - An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to...
vendor_debian·2019·CVSS 9.0
CVE-2019-11461 [CRITICAL] CVE-2019-11461: nautilus - An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to...
An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.
Scope: local
bookworm: resolved (fixed in 3.30.5-2)
bullseye: resolved (fixed in 3.30.5-2)
forky: resolved (fixed in 3.30.5-2)
sid: resolved (fixed in 3.30.5-2)
trixie: resolved (fixed in 3.30.5-2)
GHSA
GHSA-jjgg-8c74-rh96: An issue was discovered in GNOME Nautilus 3
ghsa_unreviewed·2022-05-24·CVSS 9.0
CVE-2019-11461 [CRITICAL] GHSA-jjgg-8c74-rh96: An issue was discovered in GNOME Nautilus 3
An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.
OSV
CVE-2019-11461: An issue was discovered in GNOME Nautilus 3
osv·2019-04-22·CVSS 9.0
CVE-2019-11461 [CRITICAL] CVE-2019-11461: An issue was discovered in GNOME Nautilus 3
An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11461 nautilus: sandbox security bypass [fedora-all]
bugzilla·2019-05-17·CVSS 7.8
CVE-2019-11461 [HIGH] CVE-2019-11461 nautilus: sandbox security bypass [fedora-all]
CVE-2019-11461 nautilus: sandbox security bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
Bugzilla
CVE-2019-11461 nautilus: sandbox security bypass
bugzilla·2019-05-17·CVSS 9.0
CVE-2019-11461 [CRITICAL] CVE-2019-11461 nautilus: sandbox security bypass
CVE-2019-11461 nautilus: sandbox security bypass
An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.
Reference:
https://gitlab.gnome.org/GNOME/nautilus/issues/987
Discussion:
Created nautilus tracking bugs for this issue:
Affects: fedora-all [bug 1711145]
---
Analysis:
This is the same issue as CVE-2019-10063 except that this one affects the nautilus package usi
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00088.htmlhttps://gitlab.gnome.org/GNOME/nautilus/issues/987https://security.gentoo.org/glsa/201908-27http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00088.htmlhttps://gitlab.gnome.org/GNOME/nautilus/issues/987https://security.gentoo.org/glsa/201908-27
2019-04-22
Published