USN-4872-1: Axel vulnerability
15 March 2021
Axel could be made to expose sensitive information over the network.
Releases
Packages
- axel - light command line download accelerator
Details
It was discovered that Axel did not properly verify the certificates for hostnames. An
attacker could use this vulnerability to impersonate another server and obtain
sensitive information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
-
axel
-
2.17.5-1ubuntu1+esm1
Available with Ubuntu Pro
Ubuntu 18.04
-
axel
-
2.16.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.