CVE-2019-15795 describes a vulnerability in python-apt versions 1.9.0ubuntu1 and earlier, affecting Canonical and Debian distributions. The flaw lies in its reliance solely on MD5 sums for downloaded package integrity checks, making it susceptible to man-in-the-middle (MitM) attacks. A successful MitM attack could lead to the installation of altered or malicious packages, compromising system integrity. This vulnerability is rated Medium severity (CVSS 4.7) due to its network attack vector and high attack complexity, requiring user interaction. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.0CPE matchmatch criteria | cpe:2.3:a:ubuntu:python-apt:0.8.0:ubuntu9:*:*:*:*:*:* | ||
0.8.1CPE matchmatch criteria | cpe:2.3:a:ubuntu:python-apt:0.8.1:ubuntu1:*:*:*:*:*:* | ||
0.8.3CPE matchmatch criteria | cpe:2.3:a:ubuntu:python-apt:0.8.3:ubuntu1:*:*:*:*:*:* | ||
0.8.3CPE matchmatch criteria | cpe:2.3:a:ubuntu:python-apt:0.8.3:ubuntu2:*:*:*:*:*:* | ||
0.8.3CPE matchmatch criteria | cpe:2.3:a:ubuntu:python-apt:0.8.3:ubuntu3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.