Several issues have been found in python-apt, a python interface to libapt-pkg. CVE-2019-15795 . Package : python-apt Version : 0.9.3.13 CVE ID : CVE-2019-15795 CVE-2019-15796 Debian Bug : 944696 Several issues have been found in python-apt, a python interface to libapt-pkg. CVE-2019-15795 It was discovered that python-apt would still use MD5 hashes to validate certain downloaded packages. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages. CVE-2019-15796 It was discovered that python-apt could install packages from untrusted repositories, contrary to expectations. For Debian 8 "Jessie", these problems have been fixed in version 0.9.3.13. We recommend that you upgrade your python-apt packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Numerous vulnerabilities have been identified in python-apt, necessitating updates for Debian 8 to safeguard package fidelity from potential risks.. python apt issues, debian package security, software update guide. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.