CVE-2020-16128
published 2020-12-09CVE-2020-16128: The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This…
PriorityP413low3.8CVSS 3.1
AVLACLPRLUINSCCLINAN
EPSS
0.34%
25.5th percentile
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | aptdaemon | >= 0 < 1.1.1+bzr982-0ubuntu14.5 | 1.1.1+bzr982-0ubuntu14.5 |
| canonical | aptdaemon | >= 0 < 1.1.1+bzr982-0ubuntu19.5 | 1.1.1+bzr982-0ubuntu19.5 |
| canonical | aptdaemon | >= 0 < 1.1.1+bzr982-0ubuntu32.3 | 1.1.1+bzr982-0ubuntu32.3 |
| canonical | aptdaemon | >= 1.1.1+bzr982-0ubuntu14 < 1.1.1+bzr982-0ubuntu14.5 | 1.1.1+bzr982-0ubuntu14.5 |
| canonical | aptdaemon | >= 1.1.1+bzr982-0ubuntu19 < 1.1.1+bzr982-0ubuntu19.5 | 1.1.1+bzr982-0ubuntu19.5 |
| canonical | aptdaemon | >= 1.1.1+bzr982-0ubuntu32 < 1.1.1+bzr982-0ubuntu32.3 | 1.1.1+bzr982-0ubuntu32.3 |
| canonical | aptdaemon | >= 1.1.1+bzr982-0ubuntu34 < 1.1.1+bzr982-0ubuntu34.1 | 1.1.1+bzr982-0ubuntu34.1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
CVSS provenance
nvdv3.13.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.8LOW
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Aptdaemon vulnerabilities
vendor_ubuntu·2020-12-08·CVSS 3.8
CVE-2020-27349 [LOW] Aptdaemon vulnerabilities
Title: Aptdaemon vulnerabilities
Summary: Several security issues were fixed in Aptdaemon.
Kevin Backhouse discovered that Aptdaemon incorrectly handled certain
properties. A local attacker could use this issue to test for the presence
of local files. (CVE-2020-16128)
Kevin Backhouse discovered that Aptdaemon incorrectly handled permission
checks. A local attacker could possibly use this issue to cause a denial of
service. (CVE-2020-27349)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
GHSA
GHSA-hpfw-6cc8-9hhj: The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196
ghsa_unreviewed·2022-05-24
CVE-2020-16128 [LOW] CWE-209 GHSA-hpfw-6cc8-9hhj: The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
OSV
aptdaemon vulnerabilities
osv·2020-12-08·CVSS 3.8
CVE-2020-16128 [LOW] aptdaemon vulnerabilities
aptdaemon vulnerabilities
Kevin Backhouse discovered that Aptdaemon incorrectly handled certain
properties. A local attacker could use this issue to test for the presence
of local files. (CVE-2020-16128)
Kevin Backhouse discovered that Aptdaemon incorrectly handled permission
checks. A local attacker could possibly use this issue to cause a denial of
service. (CVE-2020-27349)
OSV
CVE-2020-16128: The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196
osv·2020-12-08·CVSS 3.8
CVE-2020-16128 [LOW] CVE-2020-16128: The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-09
Published