2.6
CVSSv2

CVE-2019-15796

Published: 26/03/2020 Updated: 19/10/2020
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 4.7 | Impact Score: 2.7 | Exploitability Score: 1.6
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and previous versions. This allows downloads from unsigned repositories which shouldn't be allowed and has been fixed in verisions 1.9.5, 1.9.0ubuntu1.2, 1.6.5ubuntu0.1, 1.1.0~beta1ubuntu0.16.04.7, 0.9.3.5ubuntu3+esm2, and 0.8.3ubuntu7.5.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ubuntu python-apt 0.8.0

ubuntu python-apt 0.8.1

ubuntu python-apt 0.8.3

ubuntu python-apt 0.8.9.1

ubuntu python-apt 0.9.0

ubuntu python-apt 0.9.1

ubuntu python-apt 0.9.3.1

ubuntu python-apt 0.9.3.2

ubuntu python-apt 0.9.3.3

ubuntu python-apt 0.9.3.4

ubuntu python-apt 0.9.3.5

ubuntu python-apt 1.0.1

ubuntu python-apt 1.1.0

debian python-apt 1.8.4

ubuntu python-apt 1.4.0

ubuntu python-apt 1.6.0

ubuntu python-apt 1.6.1

ubuntu python-apt 1.6.2

ubuntu python-apt 1.6.3

ubuntu python-apt 1.6.4

ubuntu python-apt 1.8.4

ubuntu python-apt 1.9.0

ubuntu python-apt 1.7.0

ubuntu python-apt 1.8.0

ubuntu python-apt 1.8.1

ubuntu python-apt 1.8.2

ubuntu python-apt 1.8.3

Vendor Advisories

Two security issues were found in the Python interface to the apt package manager; package downloads from unsigned repositories were incorrectly rejected and the hash validation relied on MD5 For the oldstable distribution (stretch), these problems have been fixed in version 141 For the stable distribution (buster), these problems have been fix ...
USN-4247-1 introduced a regression in python-apt ...
Several security issues were fixed in python-apt ...
Several security issues were fixed in python-apt ...