CVE-2011-2515
published 2019-11-27CVE-2011-2515: PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of…
PriorityP426medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.39%
31.5th percentile
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | packagekit | < packagekit 0.6.17-1 (bookworm) | packagekit 0.6.17-1 (bookworm) |
| packagekit | packagekit | — | — |
| packagekit | packagekit | — | — |
| packagekit | packagekit | >= 0 < 0.6.17-1 | 0.6.17-1 |
| packagekit | packagekit | >= 0 < 0.6.17-1 | 0.6.17-1 |
| packagekit | packagekit | >= 0 < 0.6.17-1 | 0.6.17-1 |
| packagekit | packagekit | >= 0 < 0.6.17-1 | 0.6.17-1 |
| packagekit_project | packagekit | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wvrq-v7hr-q8xr: PackageKit 0
ghsa_unreviewed·2022-04-22
CVE-2011-2515 [MEDIUM] GHSA-wvrq-v7hr-q8xr: PackageKit 0
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
OSV
CVE-2011-2515: PackageKit 0
osv·2019-11-27·CVSS 5.3
CVE-2011-2515 [MEDIUM] CVE-2011-2515: PackageKit 0
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
Red Hat
PackageKit: installs unsigned RPM packages as though they were signed
vendor_redhat·2011-07-01·CVSS 5.3
CVE-2011-2515 [MEDIUM] PackageKit: installs unsigned RPM packages as though they were signed
PackageKit: installs unsigned RPM packages as though they were signed
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
Package: PackageKit (Red Hat Enterprise Linux 6) - Will not fix
Package: PackageKit (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2011-2515: packagekit - PackageKit 0.6.17 allows installation of unsigned RPM packages as though they we...
vendor_debian·2011·CVSS 5.3
CVE-2011-2515 [MEDIUM] CVE-2011-2515: packagekit - PackageKit 0.6.17 allows installation of unsigned RPM packages as though they we...
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
Scope: local
bookworm: resolved (fixed in 0.6.17-1)
bullseye: resolved (fixed in 0.6.17-1)
forky: resolved (fixed in 0.6.17-1)
sid: resolved (fixed in 0.6.17-1)
trixie: resolved (fixed in 0.6.17-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed [fedora-15]
bugzilla·2011-07-01·CVSS 5.3
CVE-2011-2515 [MEDIUM] CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed [fedora-15]
CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed [fedora-15]
fedora-15 tracking bug for PackageKit: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
PackageKit-0.6.15-2.fc15 has been submitted as an update for Fedora 15.
https://admin.fedoraproject.org/updates/PackageKit-0.6.15-2.fc15
---
Package PackageKit-0.6.15-2.fc15:
* should fix your issue,
* was pushed to the Fedora 15 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing PackageKit-0.6.15-2.fc15'
as soon as you are able to.
Please
Bugzilla
CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed [fedora-rawhide]
bugzilla·2011-07-01·CVSS 5.3
CVE-2011-2515 [MEDIUM] CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed [fedora-rawhide]
CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed [fedora-rawhide]
fedora-rawhide tracking bug for PackageKit: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed
bugzilla·2011-06-29·CVSS 5.3
CVE-2011-2515 [MEDIUM] CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed
CVE-2011-2515 PackageKit: installs unsigned RPM packages as though they were signed
Created attachment 510417
Auth dialog box
when installing a self built unsigned rpm that I downloaded using epiphany I get an authentication dialog stating that Authentication is required to install a signed package (screen shot attached). I believe this is wrong in two cases:
- The package wasn't signed
- I don't believe authentication is required for a signed Package with a key that's already installed.
Versions are:
PackageKit-device-rebind-0.6.15-1.fc15.x86_64
PackageKit-0.6.15-1.fc15.x86_64
PackageKit-yum-plugin-0.6.15-1.fc15.x86_64
PackageKit-yum-0.6.15-1.fc15.x86_64
PackageKit-gtk-module-0.6.15-1.fc15.x86_64
PackageKit-gstreamer-plugin-0.6.15-1.fc15.x86_64
PackageKit-glib-0.6.15-1.fc15.x86_64
Pack
https://access.redhat.com/security/cve/cve-2011-2515https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2515https://security-tracker.debian.org/tracker/CVE-2011-2515https://www.securityfocus.com/bid/48557/infohttps://access.redhat.com/security/cve/cve-2011-2515https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2515https://security-tracker.debian.org/tracker/CVE-2011-2515https://www.securityfocus.com/bid/48557/info
2019-11-27
Published