A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.
2022-06-28T17:15:08.163
2024-11-21T06:39:48.273
Modified
CVSSv3.1: 3.3 (LOW)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | packagekit_project | packagekit | * | Yes |
| Operating System | redhat | enterprise_linux | 9.0 | Yes |