User enumeration In packagekit
Description
A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version |
|---|---|---|
debian 11 | ||
debian 12 | ||
debian 13 | ||
debian 14 | ||
rpm rhel7 | - | |
rpm rhel8 | - | |
rpm rhel9 | - | |
rpm rhel6 | - |
Aliases
1. 2. 3. 4. 5.