CVE-2020-27348
MEDIUMsnapcraft <4.4.4, <2.43.1+16.04.1, <2.43.1+18.04.1 - RCE
Title source: llmDescription
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.
Scores
CVSS v3
6.8
EPSS
0.0006
EPSS Percentile
20.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Classification
CWE
CWE-427
Status
published
Affected Products (4)
canonical/snapcraft
< 4.4.4
canonical/ubuntu_linux
canonical/ubuntu_linux
pypi/snapcraft
< 4.4.4PyPI
Timeline
Published
Dec 04, 2020
Tracked Since
Feb 18, 2026