PT-2020-12932 · Canonical+1 · Snapd+2

James Henstridge

+1

·

Published

2020-07-15

·

Updated

2020-08-05

·

CVE-2020-11934

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions snapd versions prior to 2.45.1ubuntu0.2 snapd versions prior to 2.45.1+18.04.2 snapd versions prior to 2.45.1+20.04.2
Description It was discovered that snapctl user-open allowed altering the $XDG DATA DIRS environment variable when calling the system xdg-open. The OpenURL() function in usersession/userd/launcher.go would alter $XDG DATA DIRS to append a path to a directory controlled by the calling snap. A malicious snap could exploit this to bypass intended access restrictions to control how the host system xdg-open script opens the URL and, for example, execute a script shipped with the snap without confinement. This issue did not affect Ubuntu Core systems.
Recommendations For versions prior to 2.45.1ubuntu0.2, update to version 2.45.1ubuntu0.2 or later. For versions prior to 2.45.1+18.04.2, update to version 2.45.1+18.04.2 or later. For versions prior to 2.45.1+20.04.2, update to version 2.45.1+20.04.2 or later.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11934
USN-4424-1

Affected Products

Linuxmint
Ubuntu
Snapd