Insecure digital certificates In packagekit
Description
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 1.2.1-1 | ||
debian 12 | 1.2.1-1 | ||
debian 13 | 1.2.1-1 | ||
debian 14 | 1.2.1-1 |
Aliases
1. 2. 3. 4. 5.