VYPR
Medium severity4.0NVD Advisory· Published Oct 31, 2020· Updated Jun 17, 2026

CVE-2020-15703

CVE-2020-15703

Description

There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise. This way an unprivileged user can check for the existence of any files on the system as root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
aptdaemonPyPI
< 1.1.11.1.1

Affected products

5
  • Canonical/aptdaemonv5
    Range: unspecified
  • ghsa-coords
    Range: < 1.1.1
  • cpe:2.3:a:aptdaemon_project:aptdaemon:1.1.1:bzr982-0ubuntu14.4:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:aptdaemon_project:aptdaemon:1.1.1:bzr982-0ubuntu14.4:*:*:*:*:*:*
    • cpe:2.3:a:aptdaemon_project:aptdaemon:1.1.1:bzr982-0ubuntu19.4:*:*:*:*:*:*
    • cpe:2.3:a:aptdaemon_project:aptdaemon:1.1.1:bzr982-0ubuntu32.2:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.