CVE-2013-1764: Packagekit Project Packagekit

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.

Affected products

  • Packagekit Project Packagekit: up to and including 0.8.7; version 0.8.1 only; version 0.8.2 only; version 0.8.3 only; version 0.8.4 only; version 0.8.5 only; …

Published 2014-04-16. Last modified 2026-06-16.