← Vulnerability feed

Vulnerability record · CVE-2013-1764 · published 16 April 2014

CVE-2013-1764: Packagekit project packagekit permissions and access controls vulnerability

Packagekit Project · Packagekit

The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.

2.1 CVSS 2.0 Low EPSS 0.38% · top 70.4% CWE-264 · Permissions and access controls
2.1CVSS 2.0 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.

AV:L/AC:L/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-1764 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-41651Packagekit project packagekit toctou race condition vulnerabilityPackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. Packa…EPSS 0.19%7.8CVE-2020-16122Packagekit project packagekit improper privilege management vulnerabilityPackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of…EPSS 0.34%5.5CVE-2018-1106Packagekit project packagekit improper authentication vulnerabilityAn authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed package…EPSS 0.39%5.3CVE-2011-2515Packagekit project packagekit incorrect permission assignment vulnerabilityPackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and ex…EPSS 0.39%3.3CVE-2024-0217Packagekit project packagekit use after free vulnerabilityA use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, …EPSS 0.23%3.3CVE-2022-0987Packagekit project packagekit information exposure vulnerabilityA flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to …EPSS 0.26%3.3CVE-2020-16121Packagekit project packagekit error message information leak vulnerabilityPackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user …EPSS 0.47%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed

Source: NIST National Vulnerability Database (record CVE-2013-1764), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.