• PackageKit vulnerabilities

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Thursday, September 24, 2020 12:10:02
    packagekit vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS

    Summary

    Several security issues were fixed in PackageKit.

    Software Description

    * packagekit - Provides a package management service

    Details

    Vaisha Bernard discovered that PackageKit incorrectly handled
    certain methods. A local attacker could use this issue to learn
    the MIME type of any file on the system. (CVE-2020-16121)

    Sami Niemim**ki discovered that PackageKit incorrectly handled
    local deb packages. A local user could possibly use this issue to
    install untrusted packages, contrary to expectations.
    (CVE-2020-16122)

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    packagekit - 1.1.13-2ubuntu1.1

    Ubuntu 18.04 LTS
    packagekit - 1.1.9-1ubuntu2.18.04.6

    Ubuntu 16.04 LTS
    packagekit - 0.8.17-4ubuntu6~gcc5.4ubuntu1.5

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    After a standard system update you need to reboot your computer to
    make all the necessary changes.

    References

    * CVE-2020-16121
    * CVE-2020-16122

    --- Mystic BBS v1.12 A46 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)