CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Ubuntu2Debian Linux Python AptJun 17, 2026 Dec 5, 2025 6.9 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key. |
2Debian Ubuntu2Python Apt Python AptJun 17, 2026 Mar 26, 2020 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and earlier. This allows download...Show more |
2Debian Ubuntu2Python Apt Python AptJun 17, 2026 Mar 26, 2020 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 python-apt only checks the MD5 sums of downloaded files in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py in version 1.9.0ubuntu1 and earlier. This allows a man-in-the-middle attack which could p...Show more |