Snapd是开源的一个跨平台的包管理工具。 snapd 2.54.2版本存在安全漏洞,该漏洞源于软件未能对snap内容界面和布局路径执行充分的验证,导致snap能够通过变形的内容界面和布局声明注入任意的AppArmor策略规则,从而逃脱严格的snap限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Canonical Ltd. | snapd | unspecified ~ 2.54.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-44730 | 7.8 HIGH | snapd could be made to escalate privileges and run programs as administrator |
| CVE-2021-44731 | 7.8 HIGH | snapd could be made to escalate privileges and run programs as administrator |
| CVE-2021-3155 | 3.8 LOW | snapd created ~/snap with too-wide permissions |
No comments yet