2.6
CVSSv2

CVE-2019-15795

Published: 26/03/2020 Updated: 08/04/2020
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 4.7 | Impact Score: 2.7 | Exploitability Score: 1.6
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

python-apt only checks the MD5 sums of downloaded files in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py in version 1.9.0ubuntu1 and previous versions. This allows a man-in-the-middle attack which could potentially be used to install altered packages and has been fixed in versions 1.9.0ubuntu1.2, 1.6.5ubuntu0.1, 1.1.0~beta1ubuntu0.16.04.7, 0.9.3.5ubuntu3+esm2, and 0.8.3ubuntu7.5.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ubuntu python-apt 0.8.0

ubuntu python-apt 0.8.1

ubuntu python-apt 0.8.3

ubuntu python-apt 0.8.9.1

ubuntu python-apt 0.9.0

ubuntu python-apt 0.9.1

ubuntu python-apt 0.9.3.1

ubuntu python-apt 0.9.3.2

ubuntu python-apt 0.9.3.3

ubuntu python-apt 0.9.3.4

ubuntu python-apt 0.9.3.5

ubuntu python-apt 1.0.1

ubuntu python-apt 1.1.0

debian python-apt 1.8.4

ubuntu python-apt 1.4.0

ubuntu python-apt 1.6.0

ubuntu python-apt 1.6.1

ubuntu python-apt 1.6.2

ubuntu python-apt 1.6.3

ubuntu python-apt 1.6.4

ubuntu python-apt 1.8.4

ubuntu python-apt 1.9.0

ubuntu python-apt 1.7.0

ubuntu python-apt 1.8.0

ubuntu python-apt 1.8.1

ubuntu python-apt 1.8.2

ubuntu python-apt 1.8.3

Vendor Advisories

Two security issues were found in the Python interface to the apt package manager; package downloads from unsigned repositories were incorrectly rejected and the hash validation relied on MD5 For the oldstable distribution (stretch), these problems have been fixed in version 141 For the stable distribution (buster), these problems have been fix ...
USN-4247-1 introduced a regression in python-apt ...
Several security issues were fixed in python-apt ...
Several security issues were fixed in python-apt ...