CVE-2013-1764
published 2014-04-16CVE-2013-1764: The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
PriorityP45low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.38%
30.4th percentile
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | packagekit | — | — |
| packagekit_project | packagekit | <= 0.8.7 | — |
| packagekit_project | packagekit | — | — |
| packagekit_project | packagekit | — | — |
| packagekit_project | packagekit | — | — |
| packagekit_project | packagekit | — | — |
| packagekit_project | packagekit | — | — |
| packagekit_project | packagekit | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
PackageKit: downgrade packages when using the Zypper backend
vendor_redhat·2013-07-30·CVSS 2.1
CVE-2013-1764 [LOW] PackageKit: downgrade packages when using the Zypper backend
PackageKit: downgrade packages when using the Zypper backend
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
Statement: Not vulnerable. This issue did not affect the version of PackageKit in Red Hat Enterprise Linux, as Zypper support was not included.
Package: PackageKit (Red Hat Enterprise Linux 6) - Not affected
Package: PackageKit (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-1764: packagekit - The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to d...
vendor_debian·2013·CVSS 2.1
CVE-2013-1764 [LOW] CVE-2013-1764: packagekit - The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to d...
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-9g9q-8hww-wvfx: The Zypper (aka zypp) backend in PackageKit before 0
ghsa_unreviewed·2022-05-17
CVE-2013-1764 [LOW] GHSA-9g9q-8hww-wvfx: The Zypper (aka zypp) backend in PackageKit before 0
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2013-06/msg00026.htmlhttp://www.openwall.com/lists/oss-security/2013/02/25/20https://bugs.freedesktop.org/show_bug.cgi?id=61231https://bugzilla.novell.com/show_bug.cgi?id=804983https://gitorious.org/packagekit/packagekit/commit/d3d14631042237bcfe6fb30a60e59bb6d94af425https://gitorious.org/packagekit/packagekit/source/NEWShttp://lists.opensuse.org/opensuse-updates/2013-06/msg00026.htmlhttp://www.openwall.com/lists/oss-security/2013/02/25/20https://bugs.freedesktop.org/show_bug.cgi?id=61231https://bugzilla.novell.com/show_bug.cgi?id=804983https://gitorious.org/packagekit/packagekit/commit/d3d14631042237bcfe6fb30a60e59bb6d94af425https://gitorious.org/packagekit/packagekit/source/NEWS
2014-04-16
Published