USN-4247-3: python-apt vulnerabilities
USN-4247-1 fixed several vulnerabilities in python-apt. This update provides the corresponding updates for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that python-apt would still use MD5 hashes to validate certain downloaded packages. If a remote attacker were able to perform a machine-in-the-middle attack, this flaw could potentially be used to install altered packages. (CVE-2019-15795) It was discovered that python-apt could install packages from untrusted repositories, contrary to expectations. (CVE-2019-15796)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-4247-3?
The severity of USN-4247-3 is considered moderate due to vulnerabilities associated with package validation.
How do I fix USN-4247-3?
To fix USN-4247-3, update the affected packages to the latest versions provided by the Ubuntu security team.
Which versions of Ubuntu are affected by USN-4247-3?
USN-4247-3 affects Ubuntu 12.04 ESM and Ubuntu 14.04 ESM with specific versions of python-apt and python3-apt.
What vulnerabilities are addressed in USN-4247-3?
USN-4247-3 addresses vulnerabilities related to the use of MD5 hashes for package validation.
Is that an update for already patched issues in USN-4247-1?
Yes, USN-4247-3 provides corresponding updates for issues originally patched in USN-4247-1.