CVE-2020-16122
Last modified
CVE-2020-16122 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Packagekit Project | Packagekit | All versions |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 20.04 |
References
- https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1882098Issue Tracking, Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1882098Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-16122?
How severe is CVE-2020-16122?
How do I fix CVE-2020-16122?
Are you affected by CVE-2020-16122?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
