Canonical · Snapcraft · CVE-2020-27348
**Name of the Vulnerable Software and Affected Versions**
snapcraft versions prior to 4.4.4
snapcraft versions prior to 2.43.1+16.04.1
snapcraft versions prior to 2.43.1+18.04.1
**Description**
In some conditions, a snap package built by snapcraft includes the current directory in `LD LIBRARY PATH`, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar.
**Recommendations**
For versions prior to 4.4.4, update to version 4.4.4 or later.
For versions prior to 2.43.1+16.04.1, update to version 2.43.1+16.04.1 or later.
For versions prior to 2.43.1+18.04.1, update to version 2.43.1+18.04.1 or later.
As a temporary workaround, consider restricting the use of the `LD LIBRARY PATH` variable to minimize the risk of exploitation.