python-apt 1.4.1 source package in Debian

Changelog

python-apt (1.4.1) stretch-security; urgency=high

  * SECURITY UPDATE: Check that repository is trusted before downloading
    files from it (LP: #1858973)
    - apt/cache.py: Add checks to fetch_archives() and commit()
    - apt/package.py: Add checks to fetch_binary() and fetch_source()
    - CVE-2019-15796
  * SECURITY UPDATE: Do not use MD5 for verifying downloadeds
    (Closes: #944696) (#LP: #1858972)
    - apt/package.py: Use all hashes when fetching packages, and
      check that we have trusted hashes when downloading
    - CVE-2019-15795
  * To work around the new checks, the parameter allow_unauthenticated=True
    can be passed to the functions. It defaults to the value of the
    APT::Get::AllowUnauthenticated option.
  * Cherry-pick "add pkgsrcrecord.Files.{hashes,size,path,type} getters" to
    enable apt_pkg.SourceRecords to return objects with such getters instead
    of just tuples (providing tuple-style backward compatibility).
  * Automatic changes and fixes for external regressions:
    - Adjustments to test suite and CI to fix CI regressions
    - testcommon: Avoid reading host apt.conf files
    - Automatic mirror list update

 -- Julian Andres Klode <email address hidden>  Thu, 23 Jan 2020 11:32:18 +0100

Upload details

Uploaded by:
APT Development Team
Uploaded to:
Stretch
Original maintainer:
APT Development Team
Architectures:
any all
Section:
python
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section
Stretch release main python

Builds

Downloads

File Size SHA-256 Checksum
python-apt_1.4.1.dsc 2.4 KiB 8c8bfedba3e76ed59c4d96f3b9c6db22d6193a84468b899527e1add0687c587b
python-apt_1.4.1.tar.xz 325.7 KiB 90a10a7daced35cae9096cb0bd87a6bf1c7e11a0cf201d67bcec4b3b15ab8662

No changes file available.

Binary packages built by this source