Medium
Canonical Ubuntu
It was discovered that python-apt would still use MD5 hashes to validate certain downloaded packages. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages. (CVE-2019-15795)
It was discovered that python-apt could install packages from untrusted repositories, contrary to expectations. (CVE-2019-15796)
CVEs contained in this USN include: CVE-2019-15795, CVE-2019-15796.
Severity is medium unless otherwise noted.
Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:
2020-01-22: Initial vulnerability report published.
CPE | Name | Operator | Version |
---|---|---|---|
xenial stemcells | lt | 621.55 | |
xenial stemcells | lt | 456.96 | |
xenial stemcells | lt | 315.167 | |
xenial stemcells | lt | 250.181 | |
xenial stemcells | lt | 170.201 | |
xenial stemcells | lt | 97.230 |