Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Itszn

#40270of 53,624
6.8Total CVSS
Vulnerabilities · 1
PT-2020-16674
6.8
2020-12-03
Canonical · Snapcraft · CVE-2020-27348
**Name of the Vulnerable Software and Affected Versions** snapcraft versions prior to 4.4.4 snapcraft versions prior to 2.43.1+16.04.1 snapcraft versions prior to 2.43.1+18.04.1 **Description** In some conditions, a snap package built by snapcraft includes the current directory in `LD LIBRARY PATH`, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. **Recommendations** For versions prior to 4.4.4, update to version 4.4.4 or later. For versions prior to 2.43.1+16.04.1, update to version 2.43.1+16.04.1 or later. For versions prior to 2.43.1+18.04.1, update to version 2.43.1+18.04.1 or later. As a temporary workaround, consider restricting the use of the `LD LIBRARY PATH` variable to minimize the risk of exploitation.