Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-16122

Опубликовано: 07 нояб. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1
CVSS3: 8.2

Описание

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

РелизСтатусПримечание
bionic

released

1.1.9-1ubuntu2.18.04.6
devel

released

1.1.13-2ubuntu2
esm-infra-legacy/trusty

DNE

esm-infra-legacy/xenial

released

0.8.17-4ubuntu6~gcc5.4ubuntu1.5
esm-infra/bionic

released

1.1.9-1ubuntu2.18.04.6
esm-infra/focal

released

1.1.13-2ubuntu1.1
esm-infra/xenial

released

0.8.17-4ubuntu6~gcc5.4ubuntu1.5
focal

released

1.1.13-2ubuntu1.1
precise/esm

DNE

trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 27%
0.00339
Низкий

2.1 Low

CVSS2

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 4.7
redhat
почти 6 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

CVSS3: 8.2
nvd
почти 6 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

CVSS3: 8.2
debian
почти 6 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. ...

CVSS3: 7.8
github
больше 4 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

CVSS3: 4
fstec
около 6 лет назад

Уязвимость пакетного менеджера PackageKit, связанная с ошибками управления привилегиями, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 27%
0.00339
Низкий

2.1 Low

CVSS2

8.2 High

CVSS3