CVE-2023-1523

Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.10:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*

History

21 Nov 2024, 07:39

Type Values Removed Values Added
References () https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1523 - Third Party Advisory () https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1523 - Third Party Advisory
References () https://github.com/snapcore/snapd/pull/12849 - Issue Tracking, Patch () https://github.com/snapcore/snapd/pull/12849 - Issue Tracking, Patch
References () https://marc.info/?l=oss-security&m=167879021709955&w=2 - Exploit, Mailing List () https://marc.info/?l=oss-security&m=167879021709955&w=2 - Exploit, Mailing List
References () https://ubuntu.com/security/notices/USN-6125-1 - Third Party Advisory () https://ubuntu.com/security/notices/USN-6125-1 - Third Party Advisory

08 Sep 2023, 17:17

Type Values Removed Values Added
CWE CWE-74
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 10.0
First Time Canonical ubuntu Linux
Canonical snapd
Canonical
References (MISC) https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1523 - (MISC) https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1523 - Third Party Advisory
References (MISC) https://ubuntu.com/security/notices/USN-6125-1 - (MISC) https://ubuntu.com/security/notices/USN-6125-1 - Third Party Advisory
References (MISC) https://marc.info/?l=oss-security&m=167879021709955&w=2 - (MISC) https://marc.info/?l=oss-security&m=167879021709955&w=2 - Exploit, Mailing List
References (MISC) https://github.com/snapcore/snapd/pull/12849 - (MISC) https://github.com/snapcore/snapd/pull/12849 - Issue Tracking, Patch
CPE cpe:2.3:a:canonical:snapd:*:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.10:*:*:*:-:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

01 Sep 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-01 19:15

Updated : 2024-11-21 07:39


NVD link : CVE-2023-1523

Mitre link : CVE-2023-1523

CVE.ORG link : CVE-2023-1523


JSON object : View

Products Affected

canonical

  • ubuntu_linux
  • snapd
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')