CVE-2019-11503
published 2019-04-24CVE-2019-11503: snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.42%
82.2th percentile
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | snapd | < 2.39 | 2.39 |
| debian | snapd | < snapd 2.40-1 (bookworm) | snapd 2.40-1 (bookworm) |
| snapcraft | snapd | >= 0 < 2.40-1 | 2.40-1 |
| snapcraft | snapd | >= 0 < 2.40-1 | 2.40-1 |
| snapcraft | snapd | >= 0 < 2.40-1 | 2.40-1 |
| snapcraft | snapd | >= 0 < 2.40-1 | 2.40-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w39p-qmcm-pxpm: snap-confine as included in snapd before 2
ghsa_unreviewed·2022-05-24
CVE-2019-11503 [HIGH] CWE-59 GHSA-w39p-qmcm-pxpm: snap-confine as included in snapd before 2
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."
OSV
CVE-2019-11503: snap-confine as included in snapd before 2
osv·2019-04-24·CVSS 7.5
CVE-2019-11503 [HIGH] CVE-2019-11503: snap-confine as included in snapd before 2
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."
Debian
CVE-2019-11503: snapd - snap-confine as included in snapd before 2.39 did not guard against symlink race...
vendor_debian·2019·CVSS 7.5
CVE-2019-11503 [HIGH] CVE-2019-11503: snapd - snap-confine as included in snapd before 2.39 did not guard against symlink race...
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."
Scope: local
bookworm: resolved (fixed in 2.40-1)
bullseye: resolved (fixed in 2.40-1)
forky: resolved (fixed in 2.40-1)
sid: resolved (fixed in 2.40-1)
trixie: resolved (fixed in 2.40-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11503 snapd-glib: snapd: remote attacker able to bypass security restriction [fedora-all]
bugzilla·2019-05-03·CVSS 7.5
CVE-2019-11503 [HIGH] CVE-2019-11503 snapd-glib: snapd: remote attacker able to bypass security restriction [fedora-all]
CVE-2019-11503 snapd-glib: snapd: remote attacker able to bypass security restriction [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2019-11503 snapd: remote attacker able to bypass security restriction [epel-7]
bugzilla·2019-05-03·CVSS 7.5
CVE-2019-11503 [HIGH] CVE-2019-11503 snapd: remote attacker able to bypass security restriction [epel-7]
CVE-2019-11503 snapd: remote attacker able to bypass security restriction [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the
Bugzilla
CVE-2019-11503 snapd-glib: snapd: remote attacker able to bypass security restriction [epel-7]
bugzilla·2019-05-03·CVSS 7.5
CVE-2019-11503 [HIGH] CVE-2019-11503 snapd-glib: snapd: remote attacker able to bypass security restriction [epel-7]
CVE-2019-11503 snapd-glib: snapd: remote attacker able to bypass security restriction [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template
Bugzilla
CVE-2019-11503 snapd: remote attacker able to bypass security restriction
bugzilla·2019-05-03·CVSS 7.5
CVE-2019-11503 [HIGH] CVE-2019-11503 snapd: remote attacker able to bypass security restriction
CVE-2019-11503 snapd: remote attacker able to bypass security restriction
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."
Reference:
https://www.openwall.com/lists/oss-security/2019/04/18/4
https://github.com/snapcore/snapd/pull/6642
Discussion:
Created snapd tracking bugs for this issue:
Affects: fedora-all [bug 1706018]
Created snapd-glib tracking bugs for this issue:
Affects: fedora-all [bug 1706019]
---
Created snapd tracking bugs for this issue:
Affects: epel-7 [bug 1706020]
Created snapd-glib tracking bugs for this issue:
Affects: epel-7 [bug 1706021]
---
This CVE Bugzilla entry is for community support informationa
Bugzilla
CVE-2019-11503 snapd: remote attacker able to bypass security restriction [fedora-all]
bugzilla·2019-05-03·CVSS 7.5
CVE-2019-11503 [HIGH] CVE-2019-11503 snapd: remote attacker able to bypass security restriction [fedora-all]
CVE-2019-11503 snapd: remote attacker able to bypass security restriction [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
http://www.openwall.com/lists/oss-security/2019/04/25/7https://github.com/snapcore/snapd/pull/6642https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6VACEKVQ7UAZ32WO4ZKCFW6YOBSYJ76L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VPU6APEZHAA7N2AI57OT4J2P7NKHFOLM/https://www.openwall.com/lists/oss-security/2019/04/18/4http://www.openwall.com/lists/oss-security/2019/04/25/7https://github.com/snapcore/snapd/pull/6642https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6VACEKVQ7UAZ32WO4ZKCFW6YOBSYJ76L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VPU6APEZHAA7N2AI57OT4J2P7NKHFOLM/https://www.openwall.com/lists/oss-security/2019/04/18/4
2019-04-24
Published