<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=8198&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / packagit vulnerability]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=8198</link>
		<description><![CDATA[The most recent posts in packagit vulnerability.]]></description>
		<lastBuildDate>Wed, 16 Sep 2026 12:16:57 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: packagit vulnerability]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=65593#p65593</link>
			<description><![CDATA[<p>Could it be that the fix has been backported?</p><p>The Changelog says:</p><div class="quotebox"><blockquote><div><p>packagekit (1.3.1-1+deb13u1) trixie-security; urgency=high</p><p>&#160; * Non-maintainer upload by the Security Team.<br />&#160; * Do not allow re-invoking methods on non-new transactions</p><p> -- Salvatore Bonaccorso &lt;carnil@debian.org&gt;&#160; Tue, 21 Apr 2026 16:45:57 +0200</p></div></blockquote></div><p>It doesn&#039;t mention the CVE number (which IMHO it should have to make it clear that it fixes this CVE) but this security update has been released around the same time of your article so my guess is that it relates to this CVE.<br /><a href="https://metadata.ftp-master.debian.org/changelogs//main/p/packagekit/packagekit_1.3.1-1+deb13u1_changelog" rel="nofollow">https://metadata.ftp-master.debian.org/ … _changelog</a></p>]]></description>
			<author><![CDATA[dummy@example.com (tux_99)]]></author>
			<pubDate>Wed, 16 Sep 2026 12:16:57 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=65593#p65593</guid>
		</item>
		<item>
			<title><![CDATA[Re: packagit vulnerability]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=65591#p65591</link>
			<description><![CDATA[<p>On my manually pulled up Excalibur with Cinnmon DE packagekit isn&#039;t installed (--no-install-recommends used).</p>]]></description>
			<author><![CDATA[dummy@example.com (rolfie)]]></author>
			<pubDate>Wed, 16 Sep 2026 11:06:48 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=65591#p65591</guid>
		</item>
		<item>
			<title><![CDATA[packagit vulnerability]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=65590#p65590</link>
			<description><![CDATA[<p>If we are on reporting, something else: packagekit prior to version 1.3.5 is open for intruders. I stumbled upon this while checking my servers. <br /><a href="https://cybersecuritynews.com/pack2theroot-vulnerability/" rel="nofollow">https://cybersecuritynews.com/pack2ther … erability/</a></p><p>Just checked my desktop (excalibur): packagekit is installed in version 1.3.1, hence vulnerable. </p><p>I wonder why this is actually installed by default, at least in non-gnome or non-kde installations.</p><p>At present the packagekit stuff can often be safely removed; what is not being used, should not be installed.</p><p>In another XFCE setup is had been pulled in by system-config-printer which could, luckily, also be safely removed. For the price, that printers need to be configured on the command line or using the CUPS web interface. </p><p>Now checking the servers. Both excalibur servers do not have it installed. Good.</p>]]></description>
			<author><![CDATA[dummy@example.com (beate)]]></author>
			<pubDate>Wed, 16 Sep 2026 09:17:46 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=65590#p65590</guid>
		</item>
	</channel>
</rss>
