CVE-2020-16128: Aptdaemon error messages disclosed file existence to unprivileged users via dbus properties
Last updated 25 August 2025
Other sources
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16128?
CVE-2020-16128 has been classified as a moderate severity vulnerability due to potential file existence disclosure.
How do I fix CVE-2020-16128?
To fix CVE-2020-16128, update the aptdaemon package to versions 1.1.1+bzr982-0ubuntu34.1 or higher.
Which systems are affected by CVE-2020-16128?
CVE-2020-16128 affects Ubuntu Linux versions 16.04, 18.04, 20.04, and 20.10 with specific aptdaemon versions.
What impact does CVE-2020-16128 have on my system?
CVE-2020-16128 may allow attackers to determine the existence of certain files, potentially exposing sensitive information.
Is CVE-2020-16128 a remote or local vulnerability?
CVE-2020-16128 is considered a local vulnerability as it requires local access to the system to exploit.