2.1
CVSSv2

CVE-2020-16122

Published: 07/11/2020 Updated: 21/10/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

packagekit project packagekit -

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 20.04

Vendor Advisories

Debian Bug report logs - #972229 CVE-2020-16121 CVE-2020-16122 Package: packagekit; Maintainer for packagekit is Matthias Klumpp <mak@debianorg>; Source for packagekit is src:packagekit (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 14 Oct 2020 20:48:01 UTC Severity: important Tag ...