PT-2021-19420 · Canonical+3 · Snapd+4
James Troup
+1
·
Published
2021-01-13
·
Updated
2022-04-26
·
CVE-2021-3155
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
snapd versions 2.54.2 and earlier
Description
The issue allows a local attacker to read private information due to the creation of ~/snap directories in user home directories without specifying owner-only permissions.
Recommendations
For snapd versions 2.54.2 and earlier, update to version 2.54.3+18.04, 2.54.3+20.04, or 2.54.3+21.10.1 to resolve the issue.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Ubuntu
Snapd