It was discovered that python-apt would still use MD5 hashes to validate certain downloaded packages. If a remote attacker were able to perform a machine-in-the-middle attack, this flaw could potentially be used to install altered packages. (CVE-2019-15795)
It was discovered that python-apt could install packages from untrusted repositories, contrary to expectations. (CVE-2019-15796)
{ "availability": "No subscription required", "binaries": [ { "binary_name": "python-apt", "binary_version": "1.1.0~beta1ubuntu0.16.04.7" }, { "binary_name": "python-apt-common", "binary_version": "1.1.0~beta1ubuntu0.16.04.7" }, { "binary_name": "python-apt-dbg", "binary_version": "1.1.0~beta1ubuntu0.16.04.7" }, { "binary_name": "python-apt-dev", "binary_version": "1.1.0~beta1ubuntu0.16.04.7" }, { "binary_name": "python-apt-doc", "binary_version": "1.1.0~beta1ubuntu0.16.04.7" }, { "binary_name": "python3-apt", "binary_version": "1.1.0~beta1ubuntu0.16.04.7" }, { "binary_name": "python3-apt-dbg", "binary_version": "1.1.0~beta1ubuntu0.16.04.7" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "python-apt", "binary_version": "1.6.5ubuntu0.1" }, { "binary_name": "python-apt-common", "binary_version": "1.6.5ubuntu0.1" }, { "binary_name": "python-apt-dbg", "binary_version": "1.6.5ubuntu0.1" }, { "binary_name": "python-apt-dev", "binary_version": "1.6.5ubuntu0.1" }, { "binary_name": "python-apt-doc", "binary_version": "1.6.5ubuntu0.1" }, { "binary_name": "python3-apt", "binary_version": "1.6.5ubuntu0.1" }, { "binary_name": "python3-apt-dbg", "binary_version": "1.6.5ubuntu0.1" } ] }