{"id":"UBUNTU-CVE-2016-1580","details":"The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to obtain sensitive information or gain privileges via a snap with a name starting with \"ubuntu-core.\"","modified":"2026-02-04T03:13:05.817232Z","published":"2016-04-29T00:00:00Z","related":["USN-2956-1"],"upstream":["CVE-2016-1580"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2016-1580"},{"type":"REPORT","url":"https://code.launchpad.net/~mvo/ubuntu-core-launcher/snappy-on-ubuntu/+merge/278938"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-2956-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2016-1580"}],"affected":[{"package":{"name":"ubuntu-core-launcher","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ubuntu-core-launcher@1.0.27.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.27.1"}]}],"versions":["1.0.9","1.0.10","1.0.13","1.0.14","1.0.17","1.0.18","1.0.19","1.0.20","1.0.22","1.0.23","1.0.25","1.0.25.1","1.0.27"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"ubuntu-core-launcher","binary_version":"1.0.27.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-1580.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}]}