CVE-2019-15796
4.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.6 / Impact: 2.7
Source: NVD
Description
Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and earlier. This allows downloads from unsigned repositories which shouldn't be allowed and has been fixed in verisions 1.9.5, 1.9.0ubuntu1.2, 1.6.5ubuntu0.1, 1.1.0~beta1ubuntu0.16.04.7, 0.9.3.5ubuntu3+esm2, and 0.8.3ubuntu7.5.
Affected (66)
Products: Ubuntu: Python Apt · Debian: Python Apt
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 0.8.0 ubuntu9 |
| Running on/with | Platform Versions |
|---|---|
Canonical Ubuntu Linux | Version 12.04 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 0.8.9.1 |
| Running on/with | Platform Versions |
|---|---|
Canonical Ubuntu Linux | Version 14.04 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.1 build1 |
| Running on/with | Platform Versions |
|---|---|
Canonical Ubuntu Linux | Version 16.04 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.8.4 | |
| Version 1.4.0 |
| Running on/with | Platform Versions |
|---|---|
Canonical Ubuntu Linux | Version 18.04 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.9.0 alpha0~ubuntu1 |
| Running on/with | Platform Versions |
|---|---|
Canonical Ubuntu Linux | Version 19.10 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.7.0 |
| Running on/with | Platform Versions |
|---|---|
Canonical Ubuntu Linux | Version 19.04 |
Related CWEs
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-347
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
References (4)
Timeline
No history available yet.