File Examination Vulnerability in PackageKit by Red Hat
CVE-2022-0987

3.3LOW

Key Information:

Vendor
CVE Published:
28 June 2022

What is CVE-2022-0987?

A defect was identified in PackageKit regarding the Transaction interface where certain methods inadequately examine files. This flaw enables a local user to discern the execution duration of these methods, potentially revealing the existence of files owned by root or different users. Such insights could lead to unauthorized access attempts and undermine the system's overall security.

Affected Version(s)

PackageKit All PackageKit versions

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.