Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-29069— snapd will follow archived symlinks when unpacking a filesystem

Quick assessment

Affected
Canonical snapd
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

snapd是snapcore开源的一个跨平台的包管理工具。使系统能够使用.snap文件。 snapd 2.62之前版本存在安全漏洞,该漏洞源于未能正确检查符号链接的目标,可能允许非特权用户访问特权信息。

CVSS 4.8 · Medium EPSS 0.23% · P12

Possible ATT&CK Techniques 1 AI

T1564.004 · NTFS File Attributes
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-29069

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
snapd will follow archived symlinks when unpacking a filesystem
Source: CVE Program / CVE List V5
Vulnerability Description
In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are directly read by snapd when it is extracted. An attacker who could convince a user to install a malicious snap which contained symbolic links at these paths could then cause snapd to write out the contents of the symbolic link destination into a world-readable directory. This in-turn could allow an unprivileged user to gain access to privileged information.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
资源在另一范围的外部可控制索引
Source: CVE Program / CVE List V5
Vulnerability Title
snapd 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
snapd是snapcore开源的一个跨平台的包管理工具。使系统能够使用.snap文件。 snapd 2.62之前版本存在安全漏洞,该漏洞源于未能正确检查符号链接的目标,可能允许非特权用户访问特权信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Canonical snapd 0 ~ 2.62 -

II. Public POCs for CVE-2024-29069

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-29069

请登录查看更多情报信息。

Patches & Fixes for CVE-2024-29069 (1)

Same Patch Batch · Canonical · 2024-07-25 · 3 CVEs total

CVE-2024-1724 6.3 MEDIUM snapd allows $HOME/bin symlink
CVE-2024-29068 5.8 MEDIUM snapd non-regular file indefinite blocking read

IV. Related Vulnerabilities

V. Comments for CVE-2024-29069

No comments yet


Leave a comment