Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-10294

Опубликовано: 01 июн. 2026
Источник: debian
EPSS Низкий

Описание

A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
packagekitfixed1.3.6-1package
packagekitno-dsatrixiepackage
packagekitpostponedbookwormpackage
packagekitpostponedbullseyepackage

Примечания

  • https://github.com/PackageKit/PackageKit/issues/969

  • Fixed by: https://github.com/PackageKit/PackageKit/commit/4c1994d0545dea8a66cc56d9457ff740965abaf0

EPSS

Процентиль: 13%
0.00222
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
nvd
3 месяца назад

A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
github
3 месяца назад

A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 13%
0.00222
Низкий