| Package | packagekit |
|---|---|
| Version | 1.1.5-2+deb9u3 (stretch), 1.1.12-5+deb10u1 (buster) |
Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation.
For Debian 10 buster, these problems have been fixed in version 1.1.12-5+deb10u1.
For Debian 9 stretch, these problems have been fixed in version 1.1.5-2+deb9u3.
We recommend that you upgrade your packagekit packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.