The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to obtain sensitive information or gain privileges via a snap with a name starting with ubuntu-core.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Canonical | 16.04 (including) | 16.04 (including) |
Ubuntu-core-launcher | Ubuntu | devel | * |
Ubuntu-core-launcher | Ubuntu | upstream | * |
Ubuntu-core-launcher | Ubuntu | xenial | * |