vendor:
PackageKit
by:
Vaisha Bernard
3.3
CVSS
MEDIUM
Sensitive Information Disclosure
200
CWE
Product Name: PackageKit
Affected Version From: 1.1.1+bzr982-0ubuntu32.1
Affected Version To: 1.1.13-2ubuntu1
Patch Exists: YES
Related CWE: N/A
CPE: a:freedesktop:packagekit
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 16.04 - 20.04
2020
File Existence Disclosure in PackageKit < 1.1.13-2ubuntu1
The InstallFiles, GetFilesLocal and GetDetailsLocal methods of the d-bus interface to PackageKit accesses given files before checking for authorization. This allows non-privileged users to learn the MIME type of any file on the system.
Mitigation:
Ensure that authorization is checked before accessing files.