It was discovered that python-apt would still use MD5 hashes to validate certain downloaded packages. If a remote attacker were able to perform a machine-in-the-middle attack, this flaw could potentially be used to install altered packages. (CVE-2019-15795)
It was discovered that python-apt could install packages from untrusted repositories, contrary to expectations. (CVE-2019-15796)
{
"binaries": [
{
"binary_name": "python-apt",
"binary_version": "1.1.0~beta1ubuntu0.16.04.7"
},
{
"binary_name": "python-apt-common",
"binary_version": "1.1.0~beta1ubuntu0.16.04.7"
},
{
"binary_name": "python-apt-dev",
"binary_version": "1.1.0~beta1ubuntu0.16.04.7"
},
{
"binary_name": "python3-apt",
"binary_version": "1.1.0~beta1ubuntu0.16.04.7"
}
],
"availability": "No subscription required"
}
{
"cves": [
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2019-15795"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2019-15796"
}
],
"ecosystem": "Ubuntu:16.04:LTS"
}
{
"binaries": [
{
"binary_name": "python-apt",
"binary_version": "1.6.5ubuntu0.1"
},
{
"binary_name": "python-apt-common",
"binary_version": "1.6.5ubuntu0.1"
},
{
"binary_name": "python-apt-dev",
"binary_version": "1.6.5ubuntu0.1"
},
{
"binary_name": "python3-apt",
"binary_version": "1.6.5ubuntu0.1"
}
],
"availability": "No subscription required"
}
{
"cves": [
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2019-15795"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2019-15796"
}
],
"ecosystem": "Ubuntu:18.04:LTS"
}