Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: canonical
Published: 2019-04-23T15:57:32.649432Z
Updated: 2024-09-16T18:38:22.569Z
Reserved: 2019-02-01T00:00:00
Link: CVE-2019-7304
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2019-04-23T16:29:10.797
Modified: 2022-11-30T21:52:11.113
Link: CVE-2019-7304
Redhat
No data.