First published: Sat Nov 07 2020(Updated: )
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
PackageKit | ||
Ubuntu Linux | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16121 is classified as a medium severity vulnerability.
To fix CVE-2020-16121, update PackageKit to the latest version provided by your Linux distribution.
CVE-2020-16121 can lead to information disclosure, allowing unprivileged users to obtain sensitive file information.
CVE-2020-16121 affects systems using PackageKit, particularly Ubuntu Linux 20.04 and its derivatives.
As of now, there is no public information indicating that CVE-2020-16121 is actively exploited in the wild.