Several security issues were fixed in python-apt.. =========================================================================Ubuntu Security Notice USN-4247-3 January 23, 2020 python-apt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM - Ubuntu 12.04 ESM Summary: Several security issues were fixed in python-apt. Software Description: - python-apt: Python interface to libapt-pkg Details: USN-4247-1 fixed several vulnerabilities in python-apt. This update provides the corresponding updates for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that python-apt would still use MD5 hashes to validate certain downloaded packages. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages. (CVE-2019-15795) It was discovered that python-apt could install packages from untrusted repositories, contrary to expectations. (CVE-2019-15796) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: python-apt 0.9.3.5ubuntu3+esm2 python3-apt 0.9.3.5ubuntu3+esm2 Ubuntu 12.04 ESM: python-apt 0.8.3ubuntu7.5 python3-apt 0.8.3ubuntu7.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4247-3 https://ubuntu.com/security/notices/USN-4247-1 CVE-2019-15795, CVE-2019-15796 . Updates released addressing various vulnerabilities in python-apt for Ubuntu 12.04 and 14.04 ESM installations. Ensure your systems remain secure by applying these patches!. python apt vulnerabilities, Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, package update. . LinuxSecurity.com Team
An attacker could trick APT into installing altered source packages.. =========================================================================Ubuntu Security Notice USN-2246-1 June 17, 2014 apt vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 13.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: An attacker could trick APT into installing altered source packages. Software Description: - apt: Advanced front-end for dpkg Details: Jakub Wilk discovered that APT did not correctly validate signatures when downloading source packages. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered source packages. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: apt 1.0.1ubuntu2.1 Ubuntu 13.10: apt 0.9.9.1~ubuntu3.2 Ubuntu 12.04 LTS: apt 0.8.16~exp12ubuntu10.17 Ubuntu 10.04 LTS: apt 0.7.25.3ubuntu9.15 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2246-1 CVE-2014-0478 Package Information: https://launchpad.net/ubuntu/+source/apt/1.0.1ubuntu2.1 https://launchpad.net/ubuntu/+source/apt/0.9.9.1~ubuntu3.2 https://launchpad.net/ubuntu/+source/apt/0.8.16~exp12ubuntu10.17 https://launchpad.net/ubuntu/+source/apt/0.7.25.3ubuntu9.15 . Ubuntu has a serious APT security flaw that could enable hackers to inject tampered packages via a man-in-the-middle strategy. Discover additional details.. APT Security Flaw, Ubuntu Package Update, Attack Vector. . Severity: Critical. LinuxSecurity.com Team
Something went wrong with the md5sums in yesterdays announcement.. Something went wrong with the md5sums in yesterdays announcement. They should look like the following.. Dave 614d9051d0224008dcc270e0d8b9c463 2.4.22-1.2179.nptl/x86_64/kernel-2.4.22-1.2179.nptl.x86_64.rpm b9cb0cbeb925bca8a12ba63058f15d28 2.4.22-1.2179.nptl/x86_64/kernel-source-2.4.22-1.2179.nptl.x86_64.rpm 96e738a8be19378abaaef8eee1f252d0 2.4.22-1.2179.nptl/x86_64/kernel-doc-2.4.22-1.2179.nptl.x86_64.rpm 1bd46eacb1eb5d25f0523a3aae7bea85 2.4.22-1.2179.nptl/x86_64/kernel-smp-2.4.22-1.2179.nptl.x86_64.rpm ad8953b2fa8152576888c725432ed098 2.4.22-1.2179.nptl/x86_64/kernel-debuginfo-2.4.22-1.2179.nptl.x86_64.rpm 91eceae5508c8939af5d677bee5654c7 2.4.22-1.2179.nptl/SRPMS/kernel-2.4.22-1.2179.nptl.src.rpm b9368e3c63dcd9cf8ddc72a90d669a4c 2.4.22-1.2179.nptl/i686/kernel-2.4.22-1.2179.nptl.i686.rpm ecd1a72eea8cc01c78fa8ed880a43f6f 2.4.22-1.2179.nptl/i686/kernel-smp-2.4.22-1.2179.nptl.i686.rpm fd4f04571b3d0002ad37be017e686b3f 2.4.22-1.2179.nptl/i686/kernel-debuginfo-2.4.22-1.2179.nptl.i686.rpm ed2880317a12d54c0a078e11ce979a83 2.4.22-1.2179.nptl/i386/kernel-source-2.4.22-1.2179.nptl.i386.rpm a074148ab23312a5a32db9b3a2792bdc 2.4.22-1.2179.nptl/i386/kernel-doc-2.4.22-1.2179.nptl.i386.rpm 41812eb52e21595476b00b59c7f2c9b7 2.4.22-1.2179.nptl/i386/kernel-BOOT-2.4.22-1.2179.nptl.i386.rpm 43171ce5f8683b66679f855453bbc479 2.4.22-1.2179.nptl/i386/kernel-debuginfo-2.4.22-1.2179.nptl.i386.rpm af5b012b2cc5eeb815dc8a5e69975060 2.4.22-1.2179.nptl/athlon/kernel-2.4.22-1.2179.nptl.athlon.rpm 86e216f025311cc98bc3d209698e7aa7 2.4.22-1.2179.nptl/athlon/kernel-smp-2.4.22-1.2179.nptl.athlon.rpm fcfd93b137278ceb880e774d6f07b5a6 2.4.22-1.2179.nptl/athlon/kernel-debuginfo-2.4.22-1.2179.nptl.athlon.rpm 6cac4bf3a414cde461294fa3b44b68f9 2.4.22-1.2179.nptl/i586/kernel-2.4.22-1.2179.nptl.i586.rpm 35df3c2e929a69aa4ddb07638695c329 2.4.22-1.2179.nptl/i586/kernel-debuginfo-2.4.22-1.2179.nptl.i586.rpm -- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.