CVE-2020-27348

Description

In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.

Risk Information

Base Score
6.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
EPSS Score
Exploitation Probability
0.065

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-27348 are fixed in Python-snapcraft 4.4.4Windows
easily craft snaps (USN-4661-1) snapcraft_2.43.1+16.04.1_all.debLinux
easily craft snaps (USN-4661-1) snapcraft_2.43.1+18.04.1_all.debLinux
Vulnerabilities CVE-2020-27348 are fixed in Python-snapcraft for linux 4.4.4Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234