Bug 52490 - python-apt: Multiple issues (4.4)
Summary: python-apt: Multiple issues (4.4)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 4.4
Hardware: All Linux
: P5 normal
Target Milestone: UCS 4.4-7-errata
Assignee: Quality Assurance
QA Contact: Erik Damrose
URL:
Keywords:
Depends on:
Blocks: 52544
  Show dependency treegraph
 
Reported: 2020-12-14 09:26 CET by Quality Assurance
Modified: 2021-01-04 11:04 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 0.0 () NVD


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2020-12-14 09:26:42 CET
New Debian python-apt 1.4.2 fixes:
This update addresses the following issue:
* Various memory and file descriptor leaks were found in apt-python files  python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This  issue affects: python-apt 1.1.0~beta1 versions prior to  1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4;  2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions  prior to 2.1.3ubuntu1.1; (CVE-2020-27351)
Comment 1 Quality Assurance univentionstaff 2020-12-14 10:00:39 CET
--- mirror/ftp/4.4/unmaintained/4.4-4/source/python-apt_1.4.1.dsc
+++ apt/ucs_4.4-0-errata4.4-7/source/python-apt_1.4.2.dsc
@@ -1,3 +1,16 @@
+1.4.2 [Wed, 09 Dec 2020 17:31:32 +0100] Julian Andres Klode <jak@debian.org>:
+
+  * SECURITY UPDATE: various memory and file descriptor leaks (LP: #1899193)
+    - python/arfile.cc, python/generic.h, python/tag.cc, python/tarfile.cc:
+      fix file descriptor and memory leaks
+    - python/apt_instmodule.cc, python/apt_instmodule.h, python/arfile.h:
+      Avoid reference cycle with control,data members in apt_inst.DebFile
+      objects
+    - tests/test_cve_2020_27351.py: Test cases for DebFile (others not easily
+      testable)
+    - CVE-2020-27351
+  * data/templates: Update mirror lists
+
 1.4.1 [Thu, 23 Jan 2020 11:32:18 +0100] Julian Andres Klode <jak@debian.org>:
 
   * SECURITY UPDATE: Check that repository is trusted before downloading

<http://10.200.17.11/4.4-7/#8532639862370229167>
Comment 2 Erik Damrose univentionstaff 2020-12-15 10:24:18 CET
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[4.4-7] c954186ff9 Bug #52490: python-apt 1.4.2
 doc/errata/staging/python-apt.yaml | 17 +++++++++++++++++
 1 file changed, 17 insertions(+)