USN-2956-1
Dashboard / Vulnerabilities / USN-2956-1
USN-2956-1
Summary: ubuntu-core-launcher vulnerability
Details: Zygmunt Krynicki discovered that ubuntu-core-launcher did not properly sanitize its input and contained a logic error when determining the mountpoint of bind mounts when using snaps on Ubuntu classic systems (eg, traditional desktop and server). If a user were tricked into installing a malicious snap with a crafted snap name, an attacker could perform a delayed attack to steal data or execute code within the security context of another snap. This issue did not affect Ubuntu Core systems.
References: https://ubuntu.com/security/notices/USN-2956-1, https://ubuntu.com/security/CVE-2016-1580
Affected packages
Package
Name: ubuntu-core-launcher
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
