Vulnerability Description
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Packagekit Project | Packagekit | - |
| Canonical | Ubuntu Linux | 20.04 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1888887Issue TrackingThird Party Advisory
- https://www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.htmlExploitThird Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1888887Issue TrackingThird Party Advisory
- https://www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-16121?
CVE-2020-16121 is a vulnerability with a CVSS score of 3.3 (LOW). PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
How severe is CVE-2020-16121?
CVE-2020-16121 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16121?
Check the references section above for vendor advisories and patch information. Affected products include: Packagekit Project Packagekit, Canonical Ubuntu Linux.