Vulnerability CVE-2021-3155


Published: 2022-02-17   Modified: 2022-02-18

Description:
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

Type:

CWE-276

(Incorrect Default Permissions)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Canonical -> Snapd 
Canonical -> Ubuntu linux 

 References:
https://github.com/snapcore/snapd/commit/6bcaeeccd16ed8298a301dd92f6907f88c24cc85
https://ubuntu.com/security/notices/USN-5292-1
https://github.com/snapcore/snapd/commit/7d2a966620002149891446a53cf114804808dcca

Copyright 2024, cxsecurity.com

 

Back to Top