Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu 16.04 LTS USN-2956-1 Critical: Ubuntu-Core-Launcher Snap Isolation

ubuntu
Calendar Grey April 29, 2016
Scroller Ubuntu
Ubuntu 20.04 LTS encounters a significant vulnerability related to apparmor impacting snap security, necessitating urgent patches.
ubuntu-core-launcher did not properly isolate snaps from one another.

Summary

ubuntu-core-launcher did not properly isolate snaps from one another.

Software Description:

- ubuntu-core-launcher: Snap application launcher

Details:

Zygmunt Krynicki discovered that ubuntu-core-launcher did not properly

sanitize its input and contained a logic error when determining the

mountpoint of bind mounts when using snaps on Ubuntu classic systems (eg,

traditional desktop and server). If a user were tricked into installing a

malicious snap with a crafted snap name, an attacker could perform a

delayed attack to steal data or execute code within the security context of

another snap. This issue did not affect Ubuntu Core systems.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  ubuntu-core-launcher            1.0.27.1

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-2956-1

  CVE-2016-1580

Severity
critical
Lowest
Low
Medium
High
Critical

April 29, 2016

Package Information

  https://launchpad.net/ubuntu/+source/ubuntu-core-launcher/1.0.27.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.