Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-16122

Опубликовано: 07 нояб. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 2.1
CVSS3: 8.2

Описание

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

РелизСтатусПримечание
bionic

released

1.1.9-1ubuntu2.18.04.6
devel

released

1.1.13-2ubuntu2
esm-infra-legacy/trusty

DNE

esm-infra/bionic

released

1.1.9-1ubuntu2.18.04.6
esm-infra/focal

released

1.1.13-2ubuntu1.1
esm-infra/xenial

released

0.8.17-4ubuntu6~gcc5.4ubuntu1.5
focal

released

1.1.13-2ubuntu1.1
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

Показывать по

2.1 Low

CVSS2

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 4.7
redhat
больше 5 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

CVSS3: 8.2
nvd
больше 5 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

CVSS3: 8.2
debian
больше 5 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. ...

CVSS3: 7.8
github
больше 3 лет назад

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

CVSS3: 4
fstec
больше 5 лет назад

Уязвимость пакетного менеджера PackageKit, связанная с ошибками управления привилегиями, позволяющая нарушителю оказать воздействие на целостность данных

2.1 Low

CVSS2

8.2 High

CVSS3