CVE-2011-2515Incorrect Permission Assignment in Packagekit

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 62.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 27
Latest updateApr 22

Description

PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4

Affected Packages3 packages

Also affects: Debian Linux 10.0, 8.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-wvrq-v7hr-q8xr: PackageKit 02022-04-22
OSV
CVE-2011-2515: PackageKit 02019-11-27
CVEList
CVE-2011-2515: PackageKit 02019-11-27

📋Vendor Advisories

2
Red Hat
PackageKit: installs unsigned RPM packages as though they were signed2011-07-01
Debian
CVE-2011-2515: packagekit - PackageKit 0.6.17 allows installation of unsigned RPM packages as though they we...2011

💬Community

3
Bugzilla
CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed [fedora-15]2011-07-01
Bugzilla
CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed [fedora-rawhide]2011-07-01
Bugzilla
CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed2011-06-29
CVE-2011-2515 — Incorrect Permission Assignment | cvebase