CVE Vulnerabilities

CVE-2017-14178

Improper Handling of Exceptional Conditions

Published: Feb 02, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

In snapd 2.27 through 2.29.2 the snap logs command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journalds access restrictions.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Snapd Snapcraft 2.27 (including) 2.29.2 (including)
Snapd Ubuntu artful *
Snapd Ubuntu devel *
Snapd Ubuntu trusty *
Snapd Ubuntu upstream *
Snapd Ubuntu xenial *
Snapd Ubuntu zesty *

References