Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
{
"binaries": [
{
"binary_name": "golang-github-snapcore-snapd-dev",
"binary_version": "2.34.2~14.04.1"
},
{
"binary_name": "golang-github-ubuntu-core-snappy-dev",
"binary_version": "2.34.2~14.04.1"
},
{
"binary_name": "snap-confine",
"binary_version": "2.34.2~14.04.1"
},
{
"binary_name": "snapd",
"binary_version": "2.34.2~14.04.1"
},
{
"binary_name": "snapd-xdg-open",
"binary_version": "2.34.2~14.04.1"
},
{
"binary_name": "ubuntu-core-launcher",
"binary_version": "2.34.2~14.04.1"
},
{
"binary_name": "ubuntu-core-snapd-units",
"binary_version": "2.34.2~14.04.1"
},
{
"binary_name": "ubuntu-snappy",
"binary_version": "2.34.2~14.04.1"
},
{
"binary_name": "ubuntu-snappy-cli",
"binary_version": "2.34.2~14.04.1"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "golang-github-snapcore-snapd-dev",
"binary_version": "2.34.2ubuntu0.1"
},
{
"binary_name": "golang-github-ubuntu-core-snappy-dev",
"binary_version": "2.34.2ubuntu0.1"
},
{
"binary_name": "snap-confine",
"binary_version": "2.34.2ubuntu0.1"
},
{
"binary_name": "snapd",
"binary_version": "2.34.2ubuntu0.1"
},
{
"binary_name": "snapd-xdg-open",
"binary_version": "2.34.2ubuntu0.1"
},
{
"binary_name": "ubuntu-core-launcher",
"binary_version": "2.34.2ubuntu0.1"
},
{
"binary_name": "ubuntu-core-snapd-units",
"binary_version": "2.34.2ubuntu0.1"
},
{
"binary_name": "ubuntu-snappy",
"binary_version": "2.34.2ubuntu0.1"
},
{
"binary_name": "ubuntu-snappy-cli",
"binary_version": "2.34.2ubuntu0.1"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "golang-github-snapcore-snapd-dev",
"binary_version": "2.34.2+18.04.1"
},
{
"binary_name": "golang-github-ubuntu-core-snappy-dev",
"binary_version": "2.34.2+18.04.1"
},
{
"binary_name": "snap-confine",
"binary_version": "2.34.2+18.04.1"
},
{
"binary_name": "snapd",
"binary_version": "2.34.2+18.04.1"
},
{
"binary_name": "snapd-xdg-open",
"binary_version": "2.34.2+18.04.1"
},
{
"binary_name": "ubuntu-core-launcher",
"binary_version": "2.34.2+18.04.1"
},
{
"binary_name": "ubuntu-core-snapd-units",
"binary_version": "2.34.2+18.04.1"
},
{
"binary_name": "ubuntu-snappy",
"binary_version": "2.34.2+18.04.1"
},
{
"binary_name": "ubuntu-snappy-cli",
"binary_version": "2.34.2+18.04.1"
}
],
"availability": "No subscription required"
}