CVE-2020-16122
published 2020-11-07CVE-2020-16122: PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.6th percentile
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | packagekit | < packagekit 1.2.1-1 (bookworm) | packagekit 1.2.1-1 (bookworm) |
| packagekit | packagekit | >= 0 < 1.2.1-1 | 1.2.1-1 |
| packagekit | packagekit | >= 0 < 1.2.1-1 | 1.2.1-1 |
| packagekit | packagekit | >= 0 < 1.2.1-1 | 1.2.1-1 |
| packagekit | packagekit | >= 0 < 1.2.1-1 | 1.2.1-1 |
| packagekit | packagekit | >= 0 < 0.8.17-4ubuntu6~gcc5.4ubuntu1.5 | 0.8.17-4ubuntu6~gcc5.4ubuntu1.5 |
| packagekit | packagekit | >= 0 < 1.1.9-1ubuntu2.18.04.6 | 1.1.9-1ubuntu2.18.04.6 |
| packagekit | packagekit | >= 0 < 1.1.13-2ubuntu1.1 | 1.1.13-2ubuntu1.1 |
| packagekit | packagekit | >= 0.8.17-4ubuntu < 0.8.17-4ubuntu6~gcc5.4ubuntu1.5 | 0.8.17-4ubuntu6~gcc5.4ubuntu1.5 |
| packagekit | packagekit | >= 1.1.13-2ubuntu < 1.1.13-2ubuntu1.1 | 1.1.13-2ubuntu1.1 |
| packagekit | packagekit | >= 1.1.9-1ubuntu < 1.1.9-1ubuntu2.18.04.6 | 1.1.9-1ubuntu2.18.04.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv7.8HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
PackageKit: local user could possibly use this issue to install untrusted packages
vendor_redhat·2020-09-24·CVSS 8.2
CVE-2020-16122 [HIGH] PackageKit: local user could possibly use this issue to install untrusted packages
PackageKit: local user could possibly use this issue to install untrusted packages
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Statement: PackageKit as shipped with Red Hat Enterprise Linux 6, 7, and 8 is not affected by this flaw because it uses a different backend, and the flaw is specific to the aptcc backend used for debian-based systems.
Package: PackageKit (Red Hat Enterprise Linux 6) - Not affected
Package: PackageKit (Red Hat Enterprise Linux 7) - Not affected
Package: PackageKit (Red Hat Enterprise Linux 8) - Not affected
Ubuntu
PackageKit vulnerabilities
vendor_ubuntu·2020-09-24·CVSS 3.3
CVE-2020-16121 [LOW] PackageKit vulnerabilities
Title: PackageKit vulnerabilities
Summary: Several security issues were fixed in PackageKit.
Vaisha Bernard discovered that PackageKit incorrectly handled certain
methods. A local attacker could use this issue to learn the MIME type of
any file on the system. (CVE-2020-16121)
Sami Niemimäki discovered that PackageKit incorrectly handled local deb
packages. A local user could possibly use this issue to install untrusted
packages, contrary to expectations. (CVE-2020-16122)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Debian
CVE-2020-16122: packagekit - PackageKit's apt backend mistakenly treated all local debs as trusted. The apt s...
vendor_debian·2020·CVSS 8.2
CVE-2020-16122 [HIGH] CVE-2020-16122: packagekit - PackageKit's apt backend mistakenly treated all local debs as trusted. The apt s...
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Scope: local
bookworm: resolved (fixed in 1.2.1-1)
bullseye: resolved (fixed in 1.2.1-1)
forky: resolved (fixed in 1.2.1-1)
sid: resolved (fixed in 1.2.1-1)
trixie: resolved (fixed in 1.2.1-1)
GHSA
GHSA-jfj4-x686-g8vv: PackageKit's apt backend mistakenly treated all local debs as trusted
ghsa_unreviewed·2022-05-24
CVE-2020-16122 [HIGH] CWE-345 GHSA-jfj4-x686-g8vv: PackageKit's apt backend mistakenly treated all local debs as trusted
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
OSV
CVE-2020-16122: PackageKit's apt backend mistakenly treated all local debs as trusted
osv·2020-11-07·CVSS 7.8
CVE-2020-16122 [HIGH] CVE-2020-16122: PackageKit's apt backend mistakenly treated all local debs as trusted
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
OSV
packagekit vulnerabilities
osv·2020-09-24·CVSS 3.3
CVE-2020-16121 [LOW] packagekit vulnerabilities
packagekit vulnerabilities
Vaisha Bernard discovered that PackageKit incorrectly handled certain
methods. A local attacker could use this issue to learn the MIME type of
any file on the system. (CVE-2020-16121)
Sami Niemimäki discovered that PackageKit incorrectly handled local deb
packages. A local user could possibly use this issue to install untrusted
packages, contrary to expectations. (CVE-2020-16122)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-16122 PackageKit: local user could possibly use this issue to install untrusted packages [fedora-all]
bugzilla·2020-10-02·CVSS 8.2
CVE-2020-16122 [HIGH] CVE-2020-16122 PackageKit: local user could possibly use this issue to install untrusted packages [fedora-all]
CVE-2020-16122 PackageKit: local user could possibly use this issue to install untrusted packages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2020-16122 PackageKit: local user could possibly use this issue to install untrusted packages
bugzilla·2020-10-02·CVSS 8.2
CVE-2020-16122 [HIGH] CVE-2020-16122 PackageKit: local user could possibly use this issue to install untrusted packages
CVE-2020-16122 PackageKit: local user could possibly use this issue to install untrusted packages
PackageKit incorrectly handled local deb packages. A local user could possibly use this issue to install untrusted packages, contrary to expectations.
References:
https://packetstormsecurity.com/files/159284/USN-4538-1.txt
Discussion:
Created PackageKit tracking bugs for this issue:
Affects: fedora-all [bug 1884563]
---
External References:
https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1882098
---
Statement:
PackageKit as shipped with Red Hat Enterprise Linux 6, 7, and 8 is not affected by this flaw because it uses a different backend, and the flaw is specific to the aptcc backend used for debian-based systems.
---
This bug is now closed. Further updates for individua
2020-11-07
Published