First published: Wed Dec 09 2020(Updated: )
Kevin Backhouse discovered that python-apt incorrectly handled resources. A local attacker could possibly use this issue to cause python-apt to consume resources, leading to a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python3-apt | <2.1.3ubuntu1.1 | 2.1.3ubuntu1.1 |
=20.10 | ||
All of | ||
ubuntu/python-apt | <2.0.0ubuntu0.20.04.2 | 2.0.0ubuntu0.20.04.2 |
=20.04 | ||
All of | ||
ubuntu/python3-apt | <2.0.0ubuntu0.20.04.2 | 2.0.0ubuntu0.20.04.2 |
=20.04 | ||
All of | ||
ubuntu/python-apt | <1.6.5ubuntu0.4 | 1.6.5ubuntu0.4 |
=18.04 | ||
All of | ||
ubuntu/python3-apt | <1.6.5ubuntu0.4 | 1.6.5ubuntu0.4 |
=18.04 | ||
All of | ||
ubuntu/python-apt | <1.1.0~beta1ubuntu0.16.04.10 | 1.1.0~beta1ubuntu0.16.04.10 |
=16.04 | ||
All of | ||
ubuntu/python3-apt | <1.1.0~beta1ubuntu0.16.04.10 | 1.1.0~beta1ubuntu0.16.04.10 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this advisory is USN-4668-1.
The title of this advisory is USN-4668-1: python-apt vulnerability.
The vulnerability was discovered by Kevin Backhouse.
The vulnerability can be exploited by a local attacker to cause a denial of service by consuming resources.
To fix this vulnerability, update to python-apt version 2.1.3ubuntu1.1 or later.