← voltar
CVE-2024-1724

snapd allows $HOME/bin symlink

CVSS 6.3 MEDIUMEPSS 0.3%CWE-732
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.3EPSS 0.3%KEV nãoPoC Patch
Ciclo de vida
25 jul 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Produtos afetados
Canonical · snap

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →