CVE-2020-27348
published 2020-12-04CVE-2020-27348: In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution…
PriorityP431medium6.8CVSS 3.1
AVLACLPRLUIRSUCHIHAL
EPSS
0.67%
48.6th percentile
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | snapcraft | < 4.4.4 | 4.4.4 |
| canonical | snapcraft | >= 0 < 2.43.1 | 2.43.1 |
| canonical | snapcraft | >= 0 < 4.4.4 | 4.4.4 |
| canonical | snapcraft | >= 2.43.1 < 2.43.1+16.04.1 | 2.43.1+16.04.1 |
| canonical | snapcraft | >= 4.4 < 4.4.4 | 4.4.4 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
snapcraft Access Restriction Bypass
osv·2022-05-24
CVE-2020-27348 [MEDIUM] snapcraft Access Restriction Bypass
snapcraft Access Restriction Bypass
In some conditions, a snap package built by snapcraft includes the current directory in `LD_LIBRARY_PATH`, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.
GHSA
snapcraft Access Restriction Bypass
ghsa·2022-05-24
CVE-2020-27348 [MEDIUM] CWE-427 snapcraft Access Restriction Bypass
snapcraft Access Restriction Bypass
In some conditions, a snap package built by snapcraft includes the current directory in `LD_LIBRARY_PATH`, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.
OSV
CVE-2020-27348: In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execut
osv·2020-12-04
CVE-2020-27348 CVE-2020-27348: In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execut
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.
Ubuntu
Snapcraft vulnerability
vendor_ubuntu·2020-12-03
CVE-2020-27348 Snapcraft vulnerability
Title: Snapcraft vulnerability
Summary: An intended access restriction could be bypassed in snaps built with
Snapcraft
It was discovered that Snapcraft includes the current directory when
configuring LD_LIBRARY_PATH for application commands. If a user were
tricked into installing a malicious snap or downloading a malicious
library, under certain circumstances an attacker could exploit this to
affect strict mode snaps that have access to the library and when
launched from the directory containing the library.
Instructions: For users of the snap package, Snapcraft will automatically refresh
itself to Snapcraft 4.4.4 which is unaffected. For users of the deb
package, on Ubuntu 16.04 LTS and 18.04 LTS, please perform a standard
system update. In either case, once Snapcraft has been updated,
No detection rules found.
No public exploits indexed.
2020-12-04
Published