2.1
CVSSv2

CVE-2020-16121

Published: 07/11/2020 Updated: 18/11/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

packagekit project packagekit -

canonical ubuntu linux 20.04

Vendor Advisories

Debian Bug report logs - #972229 CVE-2020-16121 CVE-2020-16122 Package: packagekit; Maintainer for packagekit is Matthias Klumpp <mak@debianorg>; Source for packagekit is src:packagekit (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 14 Oct 2020 20:48:01 UTC Severity: important Tag ...
The InstallFiles, GetFilesLocal and GetDetailsLocal methods of the DBus interface to PackageKit <= 1113 access files before checking for authorization This allows non-privileged users to learn the MIME type of any file on the system ...