CVE-2020-15703

MEDIUM

aptdaemon - Unauthenticated Path Traversal via Locale Property

Title source: llm
STIX 2.1

Description

There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise. This way an unprivileged user can check for the existence of any files on the system as root.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.html
Patch, Third Party Advisory x_refsource_misc
https://ubuntu.com/security/notices/USN-4537-1

Scores

CVSS v3 4.0
EPSS 0.0048
EPSS Percentile 37.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
aptdaemon_project/aptdaemon 1.1.1 bzr982-0ubuntu14.4 (3 CPE variants)
pypi/aptdaemon 0 - 1.1.1PyPI
Published Oct 31, 2020
Tracked Since Feb 18, 2026