PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.html | third party advisory exploit |
https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1888887 | issue tracking third party advisory |