Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-14178

Опубликовано: 02 фев. 2018
Источник: debian
EPSS Низкий

Описание

In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
snapdfixed2.30-1package
snapdnot-affectedstretchpackage

Примечания

  • https://launchpad.net/bugs/1730255

EPSS

Процентиль: 76%
0.01757
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.

CVSS3: 7.5
nvd
больше 8 лет назад

In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.

EPSS

Процентиль: 76%
0.01757
Низкий