Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-11503

Опубликовано: 24 апр. 2019
Источник: ubuntu
Приоритет: low
CVSS2: 5
CVSS3: 7.5

Описание

snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."

РелизСтатусПримечание
bionic

released

2.39.2+18.04
cosmic

released

2.39.2+18.10
devel

not-affected

2.41+19.04
disco

released

2.39.2+19.04
eoan

released

2.39.2+19.10ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was released [2.43.3~14.04]
esm-infra/bionic

released

2.39.2+18.04
esm-infra/xenial

released

2.39.2ubuntu0.2
precise/esm

DNE

trusty

ignored

end of standard support

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 7 лет назад

snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."

CVSS3: 7.5
debian
почти 7 лет назад

snap-confine as included in snapd before 2.39 did not guard against sy ...

CVSS3: 7.5
github
больше 3 лет назад

snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."

5 Medium

CVSS2

7.5 High

CVSS3