Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0987

Опубликовано: 15 мар. 2022
Источник: redhat
CVSS3: 3.3

Описание

A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6PackageKitOut of support scope
Red Hat Enterprise Linux 7PackageKitOut of support scope
Red Hat Enterprise Linux 8PackageKitFix deferred
Red Hat Enterprise Linux 9PackageKitAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2064315PackageKit: Information Disclosure in Transaction Interface via timing

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 3 лет назад

A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.

CVSS3: 3.3
nvd
больше 3 лет назад

A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.

CVSS3: 3.3
debian
больше 3 лет назад

A flaw was found in PackageKit in the way some of the methods exposed ...

CVSS3: 3.3
github
больше 3 лет назад

A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.

CVSS3: 5.5
fstec
почти 4 года назад

Уязвимость интерфейса транзакций пакетного менеджера PackageKit, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

3.3 Low

CVSS3