(CVE-2019-11460) Incomplete fix for CVE-2017-5226
This line https://gitlab.gnome.org/GNOME/gnome-desktop/blob/master/libgnome-desktop/gnome-desktop-thumbnail-script.c#L346 is intended to fix CVE-2017-5226 (Sandbox escape)
However as was recently discovered, the fix is incomplete and still allows sandbox bypass.
https://nvd.nist.gov/vuln/detail/CVE-2019-10063 https://www.exploit-db.com/exploits/46594
Here is the fix from bubblewrap https://github.com/flatpak/flatpak/commit/8e0aaf4b70d6d7c02c331c655e1a05763485085e