PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: canonical
Published: 2020-11-07T04:10:19.889638Z
Updated: 2024-09-16T16:13:16.633Z
Reserved: 2020-07-29T00:00:00
Link: CVE-2020-16122
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-11-07T04:15:12.130
Modified: 2024-11-21T05:06:48.347
Link: CVE-2020-16122
Redhat