Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The package packagekit before version 1.2.3-1 is vulnerable to information disclosure. . Arch Linux Security Advisory ASA-202106-18 ========================================= Severity: Low Date : 2021-06-01 CVE-ID : CVE-2020-16121 Package : packagekit Type : information disclosure Remote : No Link : https://security.archlinux.org/AVG-1260 Summary ====== The package packagekit before version 1.2.3-1 is vulnerable to information disclosure. Resolution ========= Upgrade to 1.2.3-1. # pacman -Syu "packagekit> =1.2.3-1" The problem has been fixed upstream in version 1.2.3. Workaround ========= None. Description ========== The InstallFiles, GetFilesLocal and GetDetailsLocal methods of the DBus interface to PackageKit
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for PackageKit ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3911-1 Rating: low References: #1104313 #1176930 Cross-References: CVE-2020-16121 Affected Products: SUSE Linux Enterprise Workstation Extension 15-SP2 SUSE Linux Enterprise Module for Desktop Applications 15-SP2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for PackageKit fixes the following issue: - CVE-2020-16121: Fixed an Information disclosure in InstallFiles, GetFilesLocal and GetDetailsLocal (bsc#1176930). - Update summary and description of gstreamer-plugin and gtk3-module. (bsc#1104313) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-WE-15-SP2-2020-3911=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP2-2020-3911=1 Package List: - SUSE Linux Enterprise Workstation Extension 15-SP2 (x86_64): PackageKit-debuginfo-1.1.13-4.14.2 PackageKit-debugsource-1.1.13-4.14.2 PackageKit-gstreamer-plugin-1.1.13-4.14.2 PackageKit-gstreamer-plugin-debuginfo-1.1.13-4.14.2 PackageKit-gtk3-module-1.1.13-4.14.2 PackageKit-gtk3-module-debuginfo-1.1.13-4.14.2 - SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (aarch64 ppc64le s390x x86_64): PackageKit-1.1.13-4.14.2 PackageKit-backend-zypp-1.1.13-4.14.2 PackageKit-backend-zypp-debuginfo-1.1.13-4.14.2 PackageKit-debuginfo-1.1.13-4.14.2 PackageKit-debugsource-1.1.13-4.14.2 PackageKit-devel-1.1.13-4.14.2 PackageKit-devel-debuginfo-1.1.13-4.14.2 libpackagekit-glib2-18-1.1.13-4.14.2 libpackagekit-glib2-18-debuginfo-1.1.13-4.14.2 libpackagekit-glib2-devel-1.1.13-4.14.2 typelib-1_0-PackageKitGlib-1_0-1.1.13-4.14.2 - SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (noarch): PackageKit-lang-1.1.13-4.14.2 References: https://www.suse.com/security/cve/CVE-2020-16121.html https://bugzilla.suse.com/1104313 https://bugzilla.suse.com/1176930 . SUSE has released a security patch for PackageKit that tackles a minor severity vulnerability related to information exposure as outlined in the related advisory.. SUSE Security Update, PackageKit Information Disclosure, Patch Instructions. . Severity: Low. LinuxSecurity.com Team
It was discovered that packagekit was subject to a vulnerability where the InstallFiles, GetFilesLocal and GetDetailsLocal methods of the DBus interface to PackageKit accesses given files before checking for authorization. This allows non-privileged users to learn the MIME type of any file on the system. (CVE-2020-16121) . MGASA-2020-0415 - Updated packagekit packages fix a security vulnerability Publication date: 13 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0415.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-16121 It was discovered that packagekit was subject to a vulnerability where the InstallFiles, GetFilesLocal and GetDetailsLocal methods of the DBus interface to PackageKit accesses given files before checking for authorization. This allows non-privileged users to learn the MIME type of any file on the system. (CVE-2020-16121) References: - https://bugs.mageia.org/show_bug.cgi?id=27321 - https://ubuntu.com/security/notices/USN-4538-1 - https://www.cve.org/CVERecord?id=CVE-2020-16121 SRPMS: - 7/core/packagekit-1.1.12-3.1.mga7 . MGASA-2020-0416 releases a patch for packagekit addressing a security vulnerability that permits unauthorized access to specific file categories.. Mageia PackageKit Security Update, PackageKit Vulnerability, Mageia Security Advisory. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in PackageKit.. =========================================================================Ubuntu Security Notice USN-4538-1 September 24, 2020 packagekit vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in PackageKit. Software Description: - packagekit: Provides a package management service Details: Vaisha Bernard discovered that PackageKit incorrectly handled certain methods. A local attacker could use this issue to learn the MIME type of any file on the system. (CVE-2020-16121) Sami Niemimäki discovered that PackageKit incorrectly handled local deb packages. A local user could possibly use this issue to install untrusted packages, contrary to expectations. (CVE-2020-16122) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: packagekit 1.1.13-2ubuntu1.1 Ubuntu 18.04 LTS: packagekit 1.1.9-1ubuntu2.18.04.6 Ubuntu 16.04 LTS: packagekit 0.8.17-4ubuntu6~gcc5.4ubuntu1.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4538-1 CVE-2020-16121, CVE-2020-16122 Package Information: https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1 https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6 https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5 . Several security flaws have been addressed in PackageKit impacting several Ubuntu LTS versions. Ensure your system is updated for enhanced protection.. Ubuntu, PackageKit, Security Update, Vulnerability Fix, System Security. . Severity: Critical.LinuxSecurity.com Team
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for PackageKit ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0128-1 Rating: moderate References: #1038425 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP4 SUSE Linux Enterprise Workstation Extension 12-SP3 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Desktop 12-SP4 SUSE Linux Enterprise Desktop 12-SP3 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for PackageKit fixes the following issues: - Fixed displaying the license agreement pop up window during package update (bsc#1038425). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP4: zypper in -t patch SUSE-SLE-WE-12-SP4-2019-128=1 - SUSE Linux Enterprise Workstation Extension 12-SP3: zypper in -t patch SUSE-SLE-WE-12-SP3-2019-128=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-128=1 - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2019-128=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-128=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-128=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-128=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-128=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP4 (x86_64): PackageKit-debuginfo-1.1.3-24.9.1 PackageKit-debugsource-1.1.3-24.9.1 PackageKit-gstreamer-plugin-1.1.3-24.9.1 PackageKit-gstreamer-plugin-debuginfo-1.1.3-24.9.1 PackageKit-gtk3-module-1.1.3-24.9.1 PackageKit-gtk3-module-debuginfo-1.1.3-24.9.1 - SUSE Linux Enterprise Workstation Extension 12-SP3 (x86_64): PackageKit-debuginfo-1.1.3-24.9.1 PackageKit-debugsource-1.1.3-24.9.1 PackageKit-gstreamer-plugin-1.1.3-24.9.1 PackageKit-gstreamer-plugin-debuginfo-1.1.3-24.9.1 PackageKit-gtk3-module-1.1.3-24.9.1 PackageKit-gtk3-module-debuginfo-1.1.3-24.9.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): PackageKit-debuginfo-1.1.3-24.9.1 PackageKit-debugsource-1.1.3-24.9.1 PackageKit-devel-1.1.3-24.9.1 PackageKit-devel-debuginfo-1.1.3-24.9.1 libpackagekit-glib2-devel-1.1.3-24.9.1 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): PackageKit-debuginfo-1.1.3-24.9.1 PackageKit-debugsource-1.1.3-24.9.1 PackageKit-devel-1.1.3-24.9.1 PackageKit-devel-debuginfo-1.1.3-24.9.1 libpackagekit-glib2-devel-1.1.3-24.9.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): PackageKit-1.1.3-24.9.1 PackageKit-backend-zypp-1.1.3-24.9.1 PackageKit-backend-zypp-debuginfo-1.1.3-24.9.1 PackageKit-debuginfo-1.1.3-24.9.1 PackageKit-debugsource-1.1.3-24.9.1 libpackagekit-glib2-18-1.1.3-24.9.1 libpackagekit-glib2-18-debuginfo-1.1.3-24.9.1 typelib-1_0-PackageKitGlib-1_0-1.1.3-24.9.1 - SUSE Linux Enterprise Server 12-SP4 (noarch): PackageKit-lang-1.1.3-24.9.1 -SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): PackageKit-1.1.3-24.9.1 PackageKit-backend-zypp-1.1.3-24.9.1 PackageKit-backend-zypp-debuginfo-1.1.3-24.9.1 PackageKit-debuginfo-1.1.3-24.9.1 PackageKit-debugsource-1.1.3-24.9.1 libpackagekit-glib2-18-1.1.3-24.9.1 libpackagekit-glib2-18-debuginfo-1.1.3-24.9.1 typelib-1_0-PackageKitGlib-1_0-1.1.3-24.9.1 - SUSE Linux Enterprise Server 12-SP3 (noarch): PackageKit-lang-1.1.3-24.9.1 - SUSE Linux Enterprise Desktop 12-SP4 (noarch): PackageKit-lang-1.1.3-24.9.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): PackageKit-1.1.3-24.9.1 PackageKit-backend-zypp-1.1.3-24.9.1 PackageKit-backend-zypp-debuginfo-1.1.3-24.9.1 PackageKit-debuginfo-1.1.3-24.9.1 PackageKit-debugsource-1.1.3-24.9.1 PackageKit-gstreamer-plugin-1.1.3-24.9.1 PackageKit-gstreamer-plugin-debuginfo-1.1.3-24.9.1 PackageKit-gtk3-module-1.1.3-24.9.1 PackageKit-gtk3-module-debuginfo-1.1.3-24.9.1 libpackagekit-glib2-18-1.1.3-24.9.1 libpackagekit-glib2-18-debuginfo-1.1.3-24.9.1 typelib-1_0-PackageKitGlib-1_0-1.1.3-24.9.1 - SUSE Linux Enterprise Desktop 12-SP3 (noarch): PackageKit-lang-1.1.3-24.9.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): PackageKit-1.1.3-24.9.1 PackageKit-backend-zypp-1.1.3-24.9.1 PackageKit-backend-zypp-debuginfo-1.1.3-24.9.1 PackageKit-debuginfo-1.1.3-24.9.1 PackageKit-debugsource-1.1.3-24.9.1 PackageKit-gstreamer-plugin-1.1.3-24.9.1 PackageKit-gstreamer-plugin-debuginfo-1.1.3-24.9.1 PackageKit-gtk3-module-1.1.3-24.9.1 PackageKit-gtk3-module-debuginfo-1.1.3-24.9.1 libpackagekit-glib2-18-1.1.3-24.9.1 libpackagekit-glib2-18-debuginfo-1.1.3-24.9.1 typelib-1_0-PackageKitGlib-1_0-1.1.3-24.9.1 References: https://bugzilla.suse.com/1038425 _______________________________________________ sle-security-updates mailinglist
Get the latest Linux and open source security news straight to your inbox.