PT-2020-6167 · Packagekit+4 · Packagekit+4

Vaisha Bernard

·

Published

2020-07-24

·

Updated

2024-06-15

·

CVE-2020-16121

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PackageKit (affected versions not specified)
Description The issue is related to the package manager PackageKit, which provided detailed error messages to unprivileged callers. These error messages exposed information about the presence and mimetype of files that the user would not be able to determine on their own. This information leak could allow an attacker to gain access to confidential data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03396
CVE-2020-16121
DLA-2399-1
MGASA-2020-0415
OESA-2021-1381
OPENSUSE-SU-2020:2292-1
OPENSUSE-SU-2020:2344-1
OPENSUSE-SU-2020_2292-1
OPENSUSE-SU-2020_2344-1
OPENSUSE-SU-2024:10605-1
SUSE-SU-2020:3845-1
SUSE-SU-2020:3909-1
SUSE-SU-2020:3911-1
SUSE-SU-2020_3845-1
SUSE-SU-2020_3909-1
SUSE-SU-2020_3911-1
USN-4538-1

Affected Products

Astra Linux
Linuxmint
Packagekit
Suse
Ubuntu