Arch Linux 804 Published by

A packagekit security update has been released for Arch Linux.



ASA-202106-18: packagekit: information disclosure


Arch Linux Security Advisory ASA-202106-18
=========================================
Severity: Low
Date : 2021-06-01
CVE-ID : CVE-2020-16121
Package : packagekit
Type : information disclosure
Remote : No
Link :   https://security.archlinux.org/AVG-1260

Summary
======
The package packagekit before version 1.2.3-1 is vulnerable to
information disclosure.

Resolution
=========
Upgrade to 1.2.3-1.

# pacman -Syu "packagekit>=1.2.3-1"

The problem has been fixed upstream in version 1.2.3.

Workaround
=========
None.

Description
==========
The InstallFiles, GetFilesLocal and GetDetailsLocal methods of the DBus
interface to PackageKit