CVE-2020-16121: PackageKit error messages leak presence and mimetype of files to unprivileged users
Published Nov 7, 2020
·Updated
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
Affected Software
2 affected components
Packagekit Project Packagekit
Ubuntu=20.04
Event History
Nov 7, 2020
CVE Published
via MITRE·04:10 AM
Data Sourced
via MITRE·04:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-16121?
CVE-2020-16121 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-16121?
To fix CVE-2020-16121, update PackageKit to the latest version provided by your Linux distribution.
3
What impact does CVE-2020-16121 have on my system?
CVE-2020-16121 can lead to information disclosure, allowing unprivileged users to obtain sensitive file information.
4
Which systems are affected by CVE-2020-16121?
CVE-2020-16121 affects systems using PackageKit, particularly Ubuntu Linux 20.04 and its derivatives.
5
Is CVE-2020-16121 active in the wild?
As of now, there is no public information indicating that CVE-2020-16121 is actively exploited in the wild.