CVE-2022-0987

⚪ Do wiadomości

Luka w PackageKit umożliwia lokalnemu użytkownikowi sprawdzenie istnienia plików należących do roota.

CVSS
3.3
EPSS
0.3%
Exploit
none
Vendor
packagekit_project
Opis źródłowy (NVD)

A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2022-06-28 17:15:08 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:17:15 UTC
Referencje