Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-14178

Опубликовано: 02 фев. 2018
Источник: debian

Описание

In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
snapdfixed2.30-1package
snapdnot-affectedstretchpackage

Примечания

  • https://launchpad.net/bugs/1730255

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.

CVSS3: 7.5
nvd
около 8 лет назад

In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.