A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function gfiletest of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
{
"binaries": [
{
"binary_version": "1.2.5-2ubuntu3.1",
"binary_name": "gir1.2-packagekitglib-1.0"
},
{
"binary_version": "1.2.5-2ubuntu3.1",
"binary_name": "gstreamer1.0-packagekit"
},
{
"binary_version": "1.2.5-2ubuntu3.1",
"binary_name": "libpackagekit-glib2-18"
},
{
"binary_version": "1.2.5-2ubuntu3.1",
"binary_name": "packagekit"
},
{
"binary_version": "1.2.5-2ubuntu3.1",
"binary_name": "packagekit-command-not-found"
},
{
"binary_version": "1.2.5-2ubuntu3.1",
"binary_name": "packagekit-docs"
},
{
"binary_version": "1.2.5-2ubuntu3.1",
"binary_name": "packagekit-gtk3-module"
},
{
"binary_version": "1.2.5-2ubuntu3.1",
"binary_name": "packagekit-tools"
}
],
"priority_reason": "Per packagekit developers this is a minor security issue"
}{
"binaries": [
{
"binary_version": "1.2.8-2ubuntu1.5",
"binary_name": "gir1.2-packagekitglib-1.0"
},
{
"binary_version": "1.2.8-2ubuntu1.5",
"binary_name": "gstreamer1.0-packagekit"
},
{
"binary_version": "1.2.8-2ubuntu1.5",
"binary_name": "libpackagekit-glib2-18"
},
{
"binary_version": "1.2.8-2ubuntu1.5",
"binary_name": "packagekit"
},
{
"binary_version": "1.2.8-2ubuntu1.5",
"binary_name": "packagekit-command-not-found"
},
{
"binary_version": "1.2.8-2ubuntu1.5",
"binary_name": "packagekit-docs"
},
{
"binary_version": "1.2.8-2ubuntu1.5",
"binary_name": "packagekit-gtk3-module"
},
{
"binary_version": "1.2.8-2ubuntu1.5",
"binary_name": "packagekit-tools"
}
],
"priority_reason": "Per packagekit developers this is a minor security issue"
}{
"binaries": [
{
"binary_version": "1.3.1-1ubuntu1.1",
"binary_name": "gir1.2-packagekitglib-1.0"
},
{
"binary_version": "1.3.1-1ubuntu1.1",
"binary_name": "gstreamer1.0-packagekit"
},
{
"binary_version": "1.3.1-1ubuntu1.1",
"binary_name": "libpackagekit-glib2-18"
},
{
"binary_version": "1.3.1-1ubuntu1.1",
"binary_name": "packagekit"
},
{
"binary_version": "1.3.1-1ubuntu1.1",
"binary_name": "packagekit-command-not-found"
},
{
"binary_version": "1.3.1-1ubuntu1.1",
"binary_name": "packagekit-docs"
},
{
"binary_version": "1.3.1-1ubuntu1.1",
"binary_name": "packagekit-gtk3-module"
},
{
"binary_version": "1.3.1-1ubuntu1.1",
"binary_name": "packagekit-tools"
}
],
"priority_reason": "Per packagekit developers this is a minor security issue"
}{
"binaries": [
{
"binary_version": "1.3.4-3ubuntu1",
"binary_name": "gir1.2-packagekitglib-1.0"
},
{
"binary_version": "1.3.4-3ubuntu1",
"binary_name": "gstreamer1.0-packagekit"
},
{
"binary_version": "1.3.4-3ubuntu1",
"binary_name": "libpackagekit-glib2-18"
},
{
"binary_version": "1.3.4-3ubuntu1",
"binary_name": "packagekit"
},
{
"binary_version": "1.3.4-3ubuntu1",
"binary_name": "packagekit-command-not-found"
},
{
"binary_version": "1.3.4-3ubuntu1",
"binary_name": "packagekit-docs"
},
{
"binary_version": "1.3.4-3ubuntu1",
"binary_name": "packagekit-gtk3-module"
}
],
"priority_reason": "Per packagekit developers this is a minor security issue"
}{
"binaries": [
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "gir1.2-packagekitglib-1.0"
},
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "gstreamer1.0-packagekit"
},
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "libpackagekit-glib2-16"
},
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "packagekit"
},
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "packagekit-backend-aptcc"
},
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "packagekit-backend-smart"
},
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "packagekit-docs"
},
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "packagekit-gtk3-module"
},
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "packagekit-tools"
},
{
"binary_version": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1",
"binary_name": "python3-packagekit"
}
],
"priority_reason": "Per packagekit developers this is a minor security issue"
}{
"binaries": [
{
"binary_version": "1.1.9-1ubuntu2.18.04.6+esm1",
"binary_name": "gir1.2-packagekitglib-1.0"
},
{
"binary_version": "1.1.9-1ubuntu2.18.04.6+esm1",
"binary_name": "gstreamer1.0-packagekit"
},
{
"binary_version": "1.1.9-1ubuntu2.18.04.6+esm1",
"binary_name": "libpackagekit-glib2-18"
},
{
"binary_version": "1.1.9-1ubuntu2.18.04.6+esm1",
"binary_name": "packagekit"
},
{
"binary_version": "1.1.9-1ubuntu2.18.04.6+esm1",
"binary_name": "packagekit-command-not-found"
},
{
"binary_version": "1.1.9-1ubuntu2.18.04.6+esm1",
"binary_name": "packagekit-docs"
},
{
"binary_version": "1.1.9-1ubuntu2.18.04.6+esm1",
"binary_name": "packagekit-gtk3-module"
},
{
"binary_version": "1.1.9-1ubuntu2.18.04.6+esm1",
"binary_name": "packagekit-tools"
}
],
"priority_reason": "Per packagekit developers this is a minor security issue"
}{
"binaries": [
{
"binary_version": "1.1.13-2ubuntu1.1+esm1",
"binary_name": "gir1.2-packagekitglib-1.0"
},
{
"binary_version": "1.1.13-2ubuntu1.1+esm1",
"binary_name": "gstreamer1.0-packagekit"
},
{
"binary_version": "1.1.13-2ubuntu1.1+esm1",
"binary_name": "libpackagekit-glib2-18"
},
{
"binary_version": "1.1.13-2ubuntu1.1+esm1",
"binary_name": "packagekit"
},
{
"binary_version": "1.1.13-2ubuntu1.1+esm1",
"binary_name": "packagekit-command-not-found"
},
{
"binary_version": "1.1.13-2ubuntu1.1+esm1",
"binary_name": "packagekit-docs"
},
{
"binary_version": "1.1.13-2ubuntu1.1+esm1",
"binary_name": "packagekit-gtk3-module"
},
{
"binary_version": "1.1.13-2ubuntu1.1+esm1",
"binary_name": "packagekit-tools"
}
],
"priority_reason": "Per packagekit developers this is a minor security issue"
}