USN-4359-2: APT vulnerability
28 May 2020
APT could be made to crash if it opened a specially crafted file.
- apt - Advanced front-end for dpkg
USN-4359-1 fixed a vulnerability in APT. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.
Original advisory details:
It was discovered that APT incorrectly handled certain filenames during
package installation. If an attacker could provide a specially crafted
package to be installed by the system administrator, this could cause APT
- USN-4359-1: apt-transport-https, libapt-pkg-doc, libapt-inst2.0, libapt-pkg-dev, apt-doc, libapt-pkg5.0, apt-utils, libapt-pkg5.90, libapt-pkg6.0, apt