Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Improper Privilege Management. PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Remediation
There is no fixed version for packagekit
.
References
CVSS Score
7.8
high severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-16122
- CWE
- CWE-269
- Snyk ID
- SNYK-DEBIAN10-PACKAGEKIT-1012669
- Disclosed
- 07 Nov, 2020
- Published
- 25 Sep, 2020