PublicDateAtUSN: 2016-04-29 Candidate: CVE-2016-1580 CRD: 2016-04-29 PublicDate: 2016-05-13 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1580 https://code.launchpad.net/~mvo/ubuntu-core-launcher/snappy-on-ubuntu/+merge/278938 https://ubuntu.com/security/notices/USN-2956-1 Description: The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to obtain sensitive information or gain privileges via a snap with a name starting with "ubuntu-core." Ubuntu-Description: Notes: jdstrand> introduced in r83 jdstrand> only affects non-Ubuntu Core systems (ie, traditional Ubuntu systems running snappy) Bugs: https://launchpad.net/bugs/1576699 Priority: high Discovered-by: Zygmunt Krynicki Assigned-to: jdstrand CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_ubuntu-core-launcher: upstream_ubuntu-core-launcher: pending precise_ubuntu-core-launcher: DNE trusty_ubuntu-core-launcher: DNE trusty/esm_ubuntu-core-launcher: DNE vivid/stable-phone-overlay_ubuntu-core-launcher: DNE vivid/ubuntu-core_ubuntu-core-launcher: not-affected (code not present) wily_ubuntu-core-launcher: not-affected (code not present) xenial_ubuntu-core-launcher: released (1.0.27.1) esm-infra/xenial_ubuntu-core-launcher: released (1.0.27.1) devel_ubuntu-core-launcher: released (1.0.28)