CVE-2019-11502

snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-04-24 21:29

Updated : 2023-12-10 12:59


NVD link : CVE-2019-11502

Mitre link : CVE-2019-11502

CVE.ORG link : CVE-2019-11502


JSON object : View

Products Affected

canonical

  • snapd
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')