CVE-2020-16122
Last modified
CVE-2020-16122 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Packagekit Project | Packagekit | All versions |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 20.04 |
References
- https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1882098Issue Tracking, Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1882098Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-16122?
How severe is CVE-2020-16122?
How do I fix CVE-2020-16122?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-16116In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted a…3.3
- CVE-2020-16117In GNOME evolution-data-server before 3.35.91, a malicious s…5.9
- CVE-2020-16118In GNOME Balsa before 2.6.0, a malicious server operator or …7.5
- CVE-2020-16119Use-after-free vulnerability in the Linux kernel exploitable…7.8
- CVE-2020-16120Overlayfs did not properly perform permission checking when …4.4
- CVE-2020-16121PackageKit provided detailed error messages to unprivileged …3.3
- CVE-2020-16123An Ubuntu-specific patch in PulseAudio created a race condit…4.7
- CVE-2020-16124Integer Overflow or Wraparound vulnerability in the XML RPC …9.8
- CVE-2020-16125gdm3 versions before 3.36.2 or 3.38.2 would start gnome-init…6.8
- CVE-2020-16126An Ubuntu-specific modification to AccountsService in versio…3.3
- CVE-2020-16127An Ubuntu-specific modification to AccountsService in versio…5.5
- CVE-2020-16128The aptdaemon DBus interface disclosed file existence disclo…3.8
Are you affected by CVE-2020-16122?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
