snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published: 2022-02-17T22:15:16

Updated: 2024-08-03T16:45:51.372Z

Reserved: 2021-01-15T00:00:00

Link: CVE-2021-3155

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-02-17T23:15:07.337

Modified: 2022-02-25T21:32:12.883

Link: CVE-2021-3155

cve-icon Redhat

No data.