Errata overview
Errata ID 633
Date 2020-01-29
Source package python-apt
Fixed in version 1.4.1
Description
This update addresses the following issues:
* Do not use MD5 for verifying downloads (CVE-2019-15795)
* Check that repository is trusted before downloading files from it
  (CVE-2019-15796)
Additional notes
CVE ID CVE-2019-15795
CVE-2019-15796
UCS Bug number #50737