Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Ubuntu 14.04 ESM: USN-4668-4 Critical: python-apt Denial Of Service

Ubuntu Large Esm H500
python-apt could be made to crash if it opened a specially crafted file.
=========================================================================Ubuntu Security Notice USN-4668-4
January 11, 2021

python-apt vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM

Summary:

python-apt could be made to crash  if it opened a specially crafted file.

Software Description:
- python-apt: Python interface to libapt-pkg

Details:

USN-4668-1 fixed a vulnerability in python-apt. This update provides
the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

 Kevin Backhouse discovered that python-apt incorrectly handled resources. A
 local attacker could possibly use this issue to cause python-apt to consume
 resources, leading to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
  python-apt                      0.9.3.5ubuntu3+esm4
  python3-apt                     0.9.3.5ubuntu3+esm4

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4668-4
  https://ubuntu.com/security/notices/USN-4668-1
  CVE-2020-27351

Ubuntu 14.04 ESM: USN-4668-4 Critical: python-apt Denial Of Service

ubuntu
Calendar Grey January 11, 2021
Dist Ubuntu Esm H88
The Ubuntu Security Notice USN-4669-5 highlights a critical flaw in python-apt that may result in a system failure upon accessing maliciously designed files.
python-apt could be made to crash if it opened a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: python-apt 0.9.3.5ubuntu3+esm4 python3-apt 0.9.3.5ubuntu3+esm4 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4668-4

https://ubuntu.com/security/notices/USN-4668-1

CVE-2020-27351

Severity
critical
Lowest
Low
Medium
High
Critical

January 11, 2021

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here