UbuntuUpdates.org

Package "python-apt"

Name: python-apt

Description:

Python interface to libapt-pkg

Latest version: 0.8.3ubuntu7.5
Release: precise (12.04)
Level: security
Repository: main

Links


Download "python-apt"


Other versions of "python-apt" in Precise

Repository Area Version
base main 0.8.3ubuntu7
updates main 0.8.3ubuntu7.5

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.8.3ubuntu7.5 2021-05-03 14:07:17 UTC

  python-apt (0.8.3ubuntu7.5) precise-security; urgency=medium

  * SECURITY UPDATE: Check that repository is trusted before downloading
    files from it (LP: #1858973)
    - apt/cache.py: Add checks to fetch_archives() and commit()
    - apt/package.py: Add checks to fetch_binary() and fetch_source()
    - CVE-2019-15796
  * SECURITY UPDATE: Do not use MD5 for verifying downloadeds
    (Closes: #944696) (#LP: #1858972)
    - apt/package.py: Use strongest hashes when fetching packages. Packages
      without a trusted hash are still accepted.
    - CVE-2019-15795
  * To work around the new checks, the parameter allow_unauthenticated=True
    can be passed to the functions. It defaults to the value of the
    APT::Get::AllowUnauthenticated option.
    - Bump Breaks aptdaemon (<< 0.43+bzr805-0ubuntu10+esm1), as it will have
      to set that parameter after having done validation.
  * Automatic changes and fixes for external regressions:
    - Adjustments to test suite and CI to fix CI regressions
    - Automatic mirror list update
    - utils/get_debian_mirrors.py: Get data from salsa
  * Make allow_unauthenticated argument to fetch_archives() optional
    - apt/cache.py

 -- Julian Andres Klode <email address hidden> Wed, 15 Jan 2020 17:54:15 +0100

1858973 python-apt downloads from untrusted sources where apt does not
1858972 python-apt uses MD5 for validation
944696 Certificate error on launchpad xmlrpc server with H...
CVE-2019-15796 python-apt: Check that repository is trusted before downloading from it
CVE-2019-15795 python-apt: Do not use MD5 for verifying downloads



About   -   Send Feedback to @ubuntu_updates