CVE-2020-27349
published 2020-12-09CVE-2020-27349: Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
20.6th percentile
Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | aptdaemon | >= 0 < 1.1.1+bzr982-0ubuntu14.5 | 1.1.1+bzr982-0ubuntu14.5 |
| canonical | aptdaemon | >= 0 < 1.1.1+bzr982-0ubuntu19.5 | 1.1.1+bzr982-0ubuntu19.5 |
| canonical | aptdaemon | >= 0 < 1.1.1+bzr982-0ubuntu32.3 | 1.1.1+bzr982-0ubuntu32.3 |
| canonical | aptdaemon | >= 1.1.1+bzr982-0ubuntu14 < 1.1.1+bzr982-0ubuntu14.5 | 1.1.1+bzr982-0ubuntu14.5 |
| canonical | aptdaemon | >= 1.1.1+bzr982-0ubuntu19 < 1.1.1+bzr982-0ubuntu19.5 | 1.1.1+bzr982-0ubuntu19.5 |
| canonical | aptdaemon | >= 1.1.1+bzr982-0ubuntu32 < 1.1.1+bzr982-0ubuntu32.3 | 1.1.1+bzr982-0ubuntu32.3 |
| canonical | aptdaemon | >= 1.1.1+bzr982-0ubuntu34 < 1.1.1+bzr982-0ubuntu34.1 | 1.1.1+bzr982-0ubuntu34.1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Aptdaemon vulnerabilities
vendor_ubuntu·2020-12-08·CVSS 3.8
CVE-2020-27349 [LOW] Aptdaemon vulnerabilities
Title: Aptdaemon vulnerabilities
Summary: Several security issues were fixed in Aptdaemon.
Kevin Backhouse discovered that Aptdaemon incorrectly handled certain
properties. A local attacker could use this issue to test for the presence
of local files. (CVE-2020-16128)
Kevin Backhouse discovered that Aptdaemon incorrectly handled permission
checks. A local attacker could possibly use this issue to cause a denial of
service. (CVE-2020-27349)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
GHSA
GHSA-qxjq-5hf8-7hff: Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges
ghsa_unreviewed·2022-05-24
CVE-2020-27349 [MEDIUM] CWE-862 GHSA-qxjq-5hf8-7hff: Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges
Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
OSV
CVE-2020-27349: Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges
osv·2020-12-08·CVSS 5.5
CVE-2020-27349 [MEDIUM] CVE-2020-27349: Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges
Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
OSV
aptdaemon vulnerabilities
osv·2020-12-08·CVSS 3.8
CVE-2020-16128 [LOW] aptdaemon vulnerabilities
aptdaemon vulnerabilities
Kevin Backhouse discovered that Aptdaemon incorrectly handled certain
properties. A local attacker could use this issue to test for the presence
of local files. (CVE-2020-16128)
Kevin Backhouse discovered that Aptdaemon incorrectly handled permission
checks. A local attacker could possibly use this issue to cause a denial of
service. (CVE-2020-27349)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-09
Published