You are not logged in.
Pages: 1
If we are on reporting, something else: packagekit prior to version 1.3.5 is open for intruders. I stumbled upon this while checking my servers.
https://cybersecuritynews.com/pack2ther … erability/
Just checked my desktop (excalibur): packagekit is installed in version 1.3.1, hence vulnerable.
I wonder why this is actually installed by default, at least in non-gnome or non-kde installations.
At present the packagekit stuff can often be safely removed; what is not being used, should not be installed.
In another XFCE setup is had been pulled in by system-config-printer which could, luckily, also be safely removed. For the price, that printers need to be configured on the command line or using the CUPS web interface.
Now checking the servers. Both excalibur servers do not have it installed. Good.
Offline
On my manually pulled up Excalibur with Cinnmon DE packagekit isn't installed (--no-install-recommends used).
Offline
Could it be that the fix has been backported?
The Changelog says:
packagekit (1.3.1-1+deb13u1) trixie-security; urgency=high
* Non-maintainer upload by the Security Team.
* Do not allow re-invoking methods on non-new transactions-- Salvatore Bonaccorso <carnil@debian.org> Tue, 21 Apr 2026 16:45:57 +0200
It doesn't mention the CVE number (which IMHO it should have to make it clear that it fixes this CVE) but this security update has been released around the same time of your article so my guess is that it relates to this CVE.
https://metadata.ftp-master.debian.org/ … _changelog
Last edited by tux_99 (2026-09-16 12:17:20)
“Either the users control the program – or the program controls the users” Richard Stallman
Offline
Pages: 1