CVE-2020-16121
Description
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
Risk Information
Base Score
3.3
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.102
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Provides a package management service (USN-4538-1) packagekit_1.1.9-1ubuntu2.18.04.6_i386.deb | Linux |
| Provides a package management service (USN-4538-1) packagekit_1.1.9-1ubuntu2.18.04.6_amd64.deb | Linux |
| Provides a package management service (USN-4538-1) packagekit_0.8.17-4ubuntu6~gcc5.4ubuntu1.5_i386.deb | Linux |
| Provides a package management service (USN-4538-1) packagekit_0.8.17-4ubuntu6~gcc5.4ubuntu1.5_amd64.deb | Linux |
| SUSE-SU-2020:3909-1(SUSE Linux Enterprise Server 12-SP5 ) libpackagekit-glib2-18-1.1.3-24.15.1.x86_64.rpm | Linux |
| SUSE-SU-2020:3909-1(SUSE Linux Enterprise Server 12-SP5 ) libpackagekit-glib2-18-debuginfo-1.1.3-24.15.1.x86_64.rpm | Linux |
| SUSE-SU-2020:3909-1(SUSE Linux Enterprise Server 12-SP5 ) PackageKit-1.1.3-24.15.1.x86_64.rpm | Linux |
| SUSE-SU-2020:3909-1(SUSE Linux Enterprise Server 12-SP5 ) PackageKit-backend-zypp-1.1.3-24.15.1.x86_64.rpm | Linux |
| SUSE-SU-2020:3909-1(SUSE Linux Enterprise Server 12-SP5 ) PackageKit-backend-zypp-debuginfo-1.1.3-24.15.1.x86_64.rpm | Linux |
| SUSE-SU-2020:3909-1(SUSE Linux Enterprise Server 12-SP5 ) PackageKit-debuginfo-1.1.3-24.15.1.x86_64.rpm | Linux |
| SUSE-SU-2020:3909-1(SUSE Linux Enterprise Server 12-SP5 ) PackageKit-debugsource-1.1.3-24.15.1.x86_64.rpm | Linux |
| SUSE-SU-2020:3909-1(SUSE Linux Enterprise Server 12-SP5 ) PackageKit-lang-1.1.3-24.15.1.noarch.rpm | Linux |
| SUSE-SU-2020:3909-1(SUSE Linux Enterprise Server 12-SP5 ) typelib-1_0-PackageKitGlib-1_0-1.1.3-24.15.1.x86_64.rpm | Linux |
| Provides a package management service (USN-4538-1) packagekit_1.1.13-2ubuntu1.1_amd64.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234