USN-4661-1

Source
https://ubuntu.com/security/notices/USN-4661-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4661-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-4661-1
Related
Published
2020-12-03T18:35:20.125286Z
Modified
2020-12-03T18:35:20.125286Z
Summary
snapcraft vulnerability
Details

It was discovered that Snapcraft includes the current directory when configuring LDLIBRARYPATH for application commands. If a user were tricked into installing a malicious snap or downloading a malicious library, under certain circumstances an attacker could exploit this to affect strict mode snaps that have access to the library and when launched from the directory containing the library.

References

Affected packages

Ubuntu:16.04:LTS / snapcraft

Package

Name
snapcraft
Purl
pkg:deb/ubuntu/snapcraft?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.43.1+16.04.1

Affected versions

0.*

0.3
0.4
0.5
0.6

1.*

1.0

2.*

2.0
2.0.1
2.1
2.1.1
2.2
2.2.1
2.2.2
2.3.1
2.3.2
2.4
2.5
2.6
2.6.1
2.7
2.8
2.8.1
2.8.2
2.8.3
2.8.4
2.8.8b
2.9
2.10.1
2.11
2.12
2.12.1
2.13.1
2.14
2.15.1
2.16
2.17
2.18.1
2.19
2.20
2.21
2.22.1
2.23
2.24
2.25
2.26
2.27
2.27.1
2.28
2.29
2.31
2.33
2.34
2.35
2.39.2
2.39.3
2.39.3+really2.35
2.40
2.41
2.42
2.42.1
2.43
2.43.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.43.1+16.04.1",
            "binary_name": "snapcraft"
        },
        {
            "binary_version": "2.43.1+16.04.1",
            "binary_name": "snapcraft-examples"
        },
        {
            "binary_version": "2.43.1+16.04.1",
            "binary_name": "snapcraft-parser"
        }
    ]
}

Ubuntu:18.04:LTS / snapcraft

Package

Name
snapcraft
Purl
pkg:deb/ubuntu/snapcraft?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.43.1+18.04.1

Affected versions

2.*

2.34+17.10
2.39.2+18.04.2
2.40+18.04.1
2.40+18.04.3
2.41+18.04.1
2.41+18.04.2
2.42+18.04.2
2.42.1+18.04
2.43+18.04
2.43.1+18.04

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.43.1+18.04.1",
            "binary_name": "snapcraft"
        },
        {
            "binary_version": "2.43.1+18.04.1",
            "binary_name": "snapcraft-examples"
        },
        {
            "binary_version": "2.43.1+18.04.1",
            "binary_name": "snapcraft-parser"
        }
    ]
}