CVE-2011-2515: Medium severity Packagekit Project Packagekit vulnerability
Published Nov 27, 2019
·Updated
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
Affected Software
6 affected componentsFixes available
Packagekit Project Packagekit=0.6.17
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
redhat Enterprise Linux Server=6.0
debian/packagekit
1.2.2-21.2.6-51.3.1-11.3.4-3
Event History
Nov 27, 2019
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
DescriptionWeakness
Feb 17, 2026
Data Sourced
via Debian·11:42 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-2515?
CVE-2011-2515 is considered a critical vulnerability due to its potential for executing arbitrary code from unsigned RPM packages.
2
How do I fix CVE-2011-2515?
To fix CVE-2011-2515, upgrade PackageKit to version 1.2.2-2, 1.2.6-5, or 1.3.0-1 as those versions address this vulnerability.
3
What versions of PackageKit are affected by CVE-2011-2515?
PackageKit version 0.6.17 is specifically affected by CVE-2011-2515.
4
Which operating systems are affected by CVE-2011-2515?
CVE-2011-2515 affects Debian Linux versions 8.0, 9.0, 10.0 and Red Hat Enterprise Linux Server version 6.0.
5
What is the impact of exploiting CVE-2011-2515?
Exploiting CVE-2011-2515 could allow an attacker to install non-trusted packages and execute potentially harmful code.