First published: Wed Nov 27 2019(Updated: )
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/packagekit | 1.2.2-2 1.2.6-5 1.3.0-1 | |
PackageKit | =0.6.17 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
redhat enterprise Linux server | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2515 is considered a critical vulnerability due to its potential for executing arbitrary code from unsigned RPM packages.
To fix CVE-2011-2515, upgrade PackageKit to version 1.2.2-2, 1.2.6-5, or 1.3.0-1 as those versions address this vulnerability.
PackageKit version 0.6.17 is specifically affected by CVE-2011-2515.
CVE-2011-2515 affects Debian Linux versions 8.0, 9.0, 10.0 and Red Hat Enterprise Linux Server version 6.0.
Exploiting CVE-2011-2515 could allow an attacker to install non-trusted packages and execute potentially harmful code.