Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-16122

Опубликовано: 24 сент. 2020
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

Отчет

PackageKit as shipped with Red Hat Enterprise Linux 6, 7, and 8 is not affected by this flaw because it uses a different backend, and the flaw is specific to the aptcc backend used for debian-based systems.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6PackageKitNot affected
Red Hat Enterprise Linux 7PackageKitNot affected
Red Hat Enterprise Linux 8PackageKitNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1884562PackageKit: local user could possibly use this issue to install untrusted packages

EPSS

Процентиль: 24%
0.0008
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 5 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

CVSS3: 8.2
nvd
больше 5 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

CVSS3: 8.2
debian
больше 5 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. ...

CVSS3: 7.8
github
больше 3 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

CVSS3: 4
fstec
больше 5 лет назад

Уязвимость пакетного менеджера PackageKit, связанная с ошибками управления привилегиями, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 24%
0.0008
Низкий

4.7 Medium

CVSS3