CVE-2020-16121

PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
Configurations

Configuration 1 (hide)

cpe:2.3:a:packagekit_project:packagekit:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*

History

21 Nov 2024, 05:06

Type Values Removed Values Added
References () https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1888887 - Issue Tracking, Third Party Advisory () https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1888887 - Issue Tracking, Third Party Advisory
References () https://www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.html - Exploit, Third Party Advisory () https://www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.html - Exploit, Third Party Advisory

Information

Published : 2020-11-07 04:15

Updated : 2024-11-21 05:06


NVD link : CVE-2020-16121

Mitre link : CVE-2020-16121

CVE.ORG link : CVE-2020-16121


JSON object : View

Products Affected

canonical

  • ubuntu_linux

packagekit_project

  • packagekit
CWE
CWE-209

Generation of Error Message Containing Sensitive Information