Package "python-apt-doc"
Name: |
python-apt-doc
|
Description: |
Python interface to libapt-pkg (API documentation)
|
Latest version: |
0.8.3ubuntu7.5 |
Release: |
precise (12.04) |
Level: |
security |
Repository: |
main |
Head package: |
python-apt |
Links
Download "python-apt-doc"
Other versions of "python-apt-doc" in Precise
Changelog
python-apt (0.8.3ubuntu7.5) precise-security; urgency=medium
* SECURITY UPDATE: Check that repository is trusted before downloading
files from it (LP: #1858973)
- apt/cache.py: Add checks to fetch_archives() and commit()
- apt/package.py: Add checks to fetch_binary() and fetch_source()
- CVE-2019-15796
* SECURITY UPDATE: Do not use MD5 for verifying downloadeds
(Closes: #944696) (#LP: #1858972)
- apt/package.py: Use strongest hashes when fetching packages. Packages
without a trusted hash are still accepted.
- CVE-2019-15795
* To work around the new checks, the parameter allow_unauthenticated=True
can be passed to the functions. It defaults to the value of the
APT::Get::AllowUnauthenticated option.
- Bump Breaks aptdaemon (<< 0.43+bzr805-0ubuntu10+esm1), as it will have
to set that parameter after having done validation.
* Automatic changes and fixes for external regressions:
- Adjustments to test suite and CI to fix CI regressions
- Automatic mirror list update
- utils/get_debian_mirrors.py: Get data from salsa
* Make allow_unauthenticated argument to fetch_archives() optional
- apt/cache.py
-- Julian Andres Klode <email address hidden> Wed, 15 Jan 2020 17:54:15 +0100
|
1858973 |
python-apt downloads from untrusted sources where apt does not |
1858972 |
python-apt uses MD5 for validation |
944696 |
Certificate error on launchpad xmlrpc server with H... |
CVE-2019-15796 |
python-apt: Check that repository is trusted before downloading from it |
CVE-2019-15795 |
python-apt: Do not use MD5 for verifying downloads |
|
About
-
Send Feedback to @ubuntu_updates