Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Niemimsa

#31210of 53,633
8.2Total CVSS
Vulnerabilities · 1
PT-2020-6168
8.2
2020-06-04
Packagekit · Packagekit · CVE-2020-16122
**Name of the Vulnerable Software and Affected Versions** PackageKit (affected versions not specified) **Description** The issue is related to PackageKit's apt backend, which incorrectly treats all local debs as trusted. This is problematic because the apt security model relies on repository trust rather than the contents of individual files. As a result, on sites with configured PolicyKit rules, users may be able to install malicious packages. The vulnerability is associated with errors in privilege management, allowing an attacker to compromise data integrity. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.