Medium severity4.0NVD Advisory· Published Oct 31, 2020· Updated Jun 17, 2026
CVE-2020-15703
CVE-2020-15703
Description
There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise. This way an unprivileged user can check for the existence of any files on the system as root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
aptdaemonPyPI | < 1.1.1 | 1.1.1 |
Affected products
5- Canonical/aptdaemonv5Range: unspecified
cpe:2.3:a:aptdaemon_project:aptdaemon:1.1.1:bzr982-0ubuntu14.4:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:aptdaemon_project:aptdaemon:1.1.1:bzr982-0ubuntu14.4:*:*:*:*:*:*
- cpe:2.3:a:aptdaemon_project:aptdaemon:1.1.1:bzr982-0ubuntu19.4:*:*:*:*:*:*
- cpe:2.3:a:aptdaemon_project:aptdaemon:1.1.1:bzr982-0ubuntu32.2:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- ubuntu.com/security/notices/USN-4537-1nvdPatchThird Party AdvisoryWEB
- www.eyecontrol.nl/blog/the-story-of-3-cves-in-ubuntu-desktop.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-wpmr-q825-x4c6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-15703ghsaADVISORY
- bugs.launchpad.net/ubuntu/+source/aptdaemon/+bug/1888235ghsaWEB
- github.com/linuxmint/aptdaemon/blob/4d24cb61575ac6fbee8d5e61ef933e6093ee0a2e/debian/patches/CVE-2020-15703.patchghsaWEB
News mentions
0No linked articles in our index yet.