Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Information Exposure. PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
Remediation
There is no fixed version for packagekit
.
References
CVSS Score
3.3
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityNone
-
AvailabilityNone
- CVE
- CVE-2020-16121
- CWE
- CWE-209
- Snyk ID
- SNYK-DEBIAN10-PACKAGEKIT-1012663
- Disclosed
- 07 Nov, 2020
- Published
- 25 Sep, 2020