CVE-2020-16121
Estado: ModificadaBaja (3.3)—
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.47%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-209
- CWE-209
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-16121",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@ubuntu.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security@ubuntu.com",
"affectedData": [
{
"vendor": "PackageKit",
"product": "PackageKit",
"versions": [
{
"status": "affected",
"version": "1.1.13-2ubuntu",
"lessThan": "1.1.13-2ubuntu1.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "1.1.9-1ubuntu2",
"lessThan": "1.1.9-1ubuntu2.18.04.6",
"versionType": "custom"
},
{
"status": "affected",
"version": "0.8.17-4ubuntu6",
"lessThan": "0.8.17-4ubuntu6~gcc5.4ubuntu1.5",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-11-07T04:15:12.053",
"references": [
{
"url": "https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1888887",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "security@ubuntu.com"
},
{
"url": "https://www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.html",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security@ubuntu.com"
},
{
"url": "https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1888887",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.html",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@ubuntu.com",
"description": [
{
"lang": "en",
"value": "CWE-209"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-209"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own."
},
{
"lang": "es",
"value": "PackageKit proporcionó mensajes de error detallados a llamadores no privilegiados que exponían información sobre la presencia de archivos y mimetype de archivos que el usuario no podría ser capaz de determinar por sí solo"
}
],
"lastModified": "2026-06-17T02:57:44.717",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:packagekit_project:packagekit:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "936ABEE2-1ADB-44EB-AF92-818E0CE9B893"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "902B8056-9E37-443B-8905-8AA93E2447FB"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@ubuntu.com"
}