CVE-2024-29069
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
25/07/2024
Last modified:
26/08/2024
Description
In snapd versions prior to 2.62, snapd failed to properly check the<br />
destination of symbolic links when extracting a snap. The snap format <br />
is a squashfs file-system image and so can contain symbolic links and<br />
other file types. Various file entries within the snap squashfs image<br />
(such as icons and desktop files etc) are directly read by snapd when<br />
it is extracted. An attacker who could convince a user to install a<br />
malicious snap which contained symbolic links at these paths could then <br />
cause snapd to write out the contents of the symbolic link destination<br />
into a world-readable directory. This in-turn could allow an unprivileged<br />
user to gain access to privileged information.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:* | 2.62 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



