Canonical

Snapd

16 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.09%
  • Published 17.02.2022 23:15:07
  • Last modified 21.11.2024 06:36:56

snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape stri...

  • EPSS 0.03%
  • Published 29.07.2020 17:15:12
  • Last modified 21.11.2024 04:58:56

cloud-init as managed by snapd on Ubuntu Core 16 and Ubuntu Core 18 devices was run without restrictions on every boot, which a physical attacker could exploit by crafting cloud-init user-data/meta-data via external media to perform arbitrary changes...

Exploit
  • EPSS 0.6%
  • Published 24.04.2019 21:29:00
  • Last modified 21.11.2024 04:21:12

snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.

Exploit
  • EPSS 0.48%
  • Published 24.04.2019 21:29:00
  • Last modified 21.11.2024 04:21:13

snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."

Exploit
  • EPSS 1.12%
  • Published 23.04.2019 16:29:10
  • Last modified 21.11.2024 04:47:57

A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; ...

Exploit
  • EPSS 82.88%
  • Published 23.04.2019 16:29:10
  • Last modified 21.11.2024 04:47:58

Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.