CVE-2020-15703
aptdaemon Information Disclosure via Improper Input Validation in Transaction class
4.0
MEDIUM
CVSS 3.1
EPSS 0.04%
Description
There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise. This way an unprivileged user can check for the existence of any files on the system as root.
How to fix CVE-2020-15703
To remediate CVE-2020-15703, upgrade the affected package to a fixed version below.
- —upgrade to 1.1.1 or later
Is CVE-2020-15703 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.1.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.0 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |