CVE-2020-15703
Summary
| CVE | CVE-2020-15703 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-31 04:15:00 UTC |
| Updated | 2020-11-17 18:37:00 UTC |
| Description | There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise. This way an unprivileged user can check for the existence of any files on the system as root. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-4537-1: Aptdaemon vulnerability | Ubuntu security notices | Ubuntu |
CONFIRM |
ubuntu.com |
Patch, Third Party Advisory |
| The story of three CVE's in Ubuntu Desktop - EYE |
MISC |
www.eyecontrol.nl |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Vaisha Bernard
Legacy QID Mappings
- 994803 Python (Pip) Security Update for aptdaemon (GHSA-wpmr-q825-x4c6)