LOW · 3.3

CVE-2022-0987

A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and kn...

Vulnerability Description

A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.

CVSS Score

3.3

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Packagekit ProjectPackagekitAll versions
RedhatEnterprise Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-0987?

CVE-2022-0987 is a vulnerability with a CVSS score of 3.3 (LOW). A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and kn...

How severe is CVE-2022-0987?

CVE-2022-0987 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-0987?

Check the references section above for vendor advisories and patch information. Affected products include: Packagekit Project Packagekit, Redhat Enterprise Linux.