PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2399-1 | packagekit security update |
![]() |
EUVD-2020-8088 | PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages. |
![]() |
USN-4538-1 | PackageKit vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-09-16T16:13:16.633Z
Reserved: 2020-07-29T00:00:00
Link: CVE-2020-16122

No data.

Status : Modified
Published: 2020-11-07T04:15:12.130
Modified: 2024-11-21T05:06:48.347
Link: CVE-2020-16122


No data.