10
CVSSv2

CVE-2016-1580

Published: 13/05/2016 Updated: 19/05/2016
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The setup_snappy_os_mounts function in the ubuntu-core-launcher package prior to 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote malicious users to obtain sensitive information or gain privileges via a snap with a name starting with "ubuntu-core."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu-core-launcher 1.0.27

Vendor Advisories

ubuntu-core-launcher did not properly isolate snaps from one another ...