{"id":"GHSA-rp8m-h266-53jh","summary":"python-apt Flawed Package Integrity Check","details":"python-apt only checks the MD5 sums of downloaded files in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py in version 1.9.0ubuntu1 and earlier. This allows a man-in-the-middle attack which could potentially be used to install altered packages and has been fixed in versions 1.9.0ubuntu1.2, 1.6.5ubuntu0.1, 1.1.0~beta1ubuntu0.16.04.7, 0.9.3.5ubuntu3+esm2, and 0.8.3ubuntu7.5.","aliases":["CVE-2019-15795"],"modified":"2023-11-01T05:43:38.359966Z","published":"2022-05-24T17:12:47Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-07-18T22:34:38Z","nvd_published_at":"2020-03-26T13:15:00Z","cwe_ids":["CWE-327"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15795"},{"type":"PACKAGE","url":"https://github.com/excid3/python-apt"},{"type":"WEB","url":"https://usn.ubuntu.com/4247-1"},{"type":"WEB","url":"https://usn.ubuntu.com/4247-3"}],"affected":[{"package":{"name":"python-apt","ecosystem":"PyPI","purl":"pkg:pypi/python-apt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.3ubuntu7.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rp8m-h266-53jh/GHSA-rp8m-h266-53jh.json"}},{"package":{"name":"python-apt","ecosystem":"PyPI","purl":"pkg:pypi/python-apt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.9.0"},{"fixed":"0.9.3.5ubuntu3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rp8m-h266-53jh/GHSA-rp8m-h266-53jh.json"}},{"package":{"name":"python-apt","ecosystem":"PyPI","purl":"pkg:pypi/python-apt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rp8m-h266-53jh/GHSA-rp8m-h266-53jh.json"}},{"package":{"name":"python-apt","ecosystem":"PyPI","purl":"pkg:pypi/python-apt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.0"},{"fixed":"1.6.5ubuntu0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rp8m-h266-53jh/GHSA-rp8m-h266-53jh.json"}},{"package":{"name":"python-apt","ecosystem":"PyPI","purl":"pkg:pypi/python-apt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.7.0"},{"fixed":"1.9.0ubuntu1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rp8m-h266-53jh/GHSA-rp8m-h266-53jh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}