packagekit vulnerabilities
A security issue affects these releases of Ubuntu and its
derivatives:
* Ubuntu 20.04 LTS
* Ubuntu 18.04 LTS
* Ubuntu 16.04 LTS
Summary
Several security issues were fixed in PackageKit.
Software Description
* packagekit - Provides a package management service
Details
Vaisha Bernard discovered that PackageKit incorrectly handled
certain methods. A local attacker could use this issue to learn
the MIME type of any file on the system. (CVE-2020-16121)
Sami Niemim**ki discovered that PackageKit incorrectly handled
local deb packages. A local user could possibly use this issue to
install untrusted packages, contrary to expectations.
(CVE-2020-16122)
Update instructions
The problem can be corrected by updating your system to the
following package versions:
Ubuntu 20.04 LTS
packagekit - 1.1.13-2ubuntu1.1
Ubuntu 18.04 LTS
packagekit - 1.1.9-1ubuntu2.18.04.6
Ubuntu 16.04 LTS
packagekit - 0.8.17-4ubuntu6~gcc5.4ubuntu1.5
To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.
After a standard system update you need to reboot your computer to
make all the necessary changes.
References
* CVE-2020-16121
* CVE-2020-16122
--- Mystic BBS v1.12 A46 (Linux/64)
* Origin: BZ&BZ BBS (21:4/110)