Bug 26621 - apt possible new security issue CVE-2020-3810
Summary: apt possible new security issue CVE-2020-3810
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Christiaan Welvaart
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
: 27728 (view as bug list)
Depends on:
Blocks:
 
Reported: 2020-05-14 22:12 CEST by David Walser
Modified: 2020-12-04 02:56 CET (History)
2 users (show)

See Also:
Source RPM: apt-0.5.15lorg3.94-35.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-05-14 22:12:42 CEST
Debian has issued an advisory today (May 14):
https://www.debian.org/security/2020/dsa-4685

I'm not sure if the ancient version we have is affected.
Comment 1 David Walser 2020-05-14 22:14:25 CEST
Ubuntu has also issued an advisory for this:
https://usn.ubuntu.com/4359-1/
Comment 2 David Walser 2020-05-22 19:57:39 CEST
Nicolas is trying to update this ancient thing, along with dpkg.

Just so it doesn't get lost, dpkg build for Mageia 7 is:
dpkg-1.19.7-2.mga7
dpkg-devel-1.19.7-2.mga7
dpkg-dev-1.19.7-2.mga7
dpkg-perl-1.19.7-2.mga7
dselect-1.19.7-2.mga7

from dpkg-1.19.7-2.mga7.src.rpm

CC: (none) => mageia

Comment 3 Christiaan Welvaart 2020-05-22 20:16:25 CEST
The 'apt' package is apt-rpm (a fork of apt) and AFAIK there is no newer version, so please do not try to update it. It also has nothing to do with dpkg as it uses librpm. Since the 'apt' package is not supposed to handle dpkg files either but only RPMs, this bug in upstream (debian) apt is not relevant.
Comment 4 David Walser 2020-05-22 20:28:09 CEST
So we still have this ancient fork of apt, which surely must be affected by some (possibly several) security vulnerabilities.  We probably don't even know what they all are, given that I'm sure nobody is studying this old code for security issues, given that nobody is using this thing anymore.  We haven't actually fixed a security issue in this package since 2014.

Status: NEW => RESOLVED
Resolution: (none) => INVALID

Comment 5 David Walser 2020-12-04 02:56:53 CET
*** Bug 27728 has been marked as a duplicate of this bug. ***

CC: (none) => zombie_ryushu


Note You need to log in before you can comment on or make changes to this bug.