It was discovered that python-apt would still use MD5 hashes to validate certain downloaded packages. If a remote attacker were able to perform a machine-in-the-middle attack, this flaw could potentially be used to install altered packages. (CVE-2019-15795)
It was discovered that python-apt could install packages from untrusted repositories, contrary to expectations. (CVE-2019-15796)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.1.0~beta1ubuntu0.16.04.7", "binary_name": "python-apt" }, { "binary_version": "1.1.0~beta1ubuntu0.16.04.7", "binary_name": "python-apt-common" }, { "binary_version": "1.1.0~beta1ubuntu0.16.04.7", "binary_name": "python-apt-dbg" }, { "binary_version": "1.1.0~beta1ubuntu0.16.04.7", "binary_name": "python-apt-dev" }, { "binary_version": "1.1.0~beta1ubuntu0.16.04.7", "binary_name": "python-apt-doc" }, { "binary_version": "1.1.0~beta1ubuntu0.16.04.7", "binary_name": "python3-apt" }, { "binary_version": "1.1.0~beta1ubuntu0.16.04.7", "binary_name": "python3-apt-dbg" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.6.5ubuntu0.1", "binary_name": "python-apt" }, { "binary_version": "1.6.5ubuntu0.1", "binary_name": "python-apt-common" }, { "binary_version": "1.6.5ubuntu0.1", "binary_name": "python-apt-dbg" }, { "binary_version": "1.6.5ubuntu0.1", "binary_name": "python-apt-dev" }, { "binary_version": "1.6.5ubuntu0.1", "binary_name": "python-apt-doc" }, { "binary_version": "1.6.5ubuntu0.1", "binary_name": "python3-apt" }, { "binary_version": "1.6.5ubuntu0.1", "binary_name": "python3-apt-dbg" } ] }