Regression: Latest apt security update returns Hash Sum mismatch for file: URI:s
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
apt (Debian) |
Fix Released
|
Unknown
|
|||
apt (Ubuntu) |
Fix Released
|
Critical
|
Michael Vogt | ||
Lucid |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Precise |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Trusty |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Utopic |
Fix Released
|
Critical
|
Michael Vogt |
Bug Description
When running 'apt-get update' on Ubuntu Lucid using 0.7.25.3ubuntu9.16 I get Hash Sum mismatch when using file: URI:s.
First time running apt-get update after cleaning /var/lib/
root@crepes:
Ign file:/mirrors/
Ign file:/mirrors/
Ign file:/mirrors/
Ign file:/mirrors/
Get:1 file: lucid-security Release.gpg [198B]
Get:2 file: lucid-security Release [57,3kB]
Hit http://
Ign http://
Ign http://
Ign http://
Ign http://
Hit http://
Hit http://
Hit http://
Hit http://
Hit http://
W: Failed to fetch file:/mirrors/
W: Failed to fetch file:/mirrors/
W: Failed to fetch file:/mirrors/
W: Failed to fetch file:/mirrors/
E: Some index files failed to download, they have been ignored, or old ones used instead.
Runnng apt-get -o Acquire:
Reverting back to 0.7.25.3ubuntu9.15 it works.
And, of course, it works if only using http: URI:s.
Looks like a regression in 0.7.25.3ubuntu9.16
CVE References
Changed in apt (Ubuntu): | |
assignee: | nobody → Michael Vogt (mvo) |
importance: | Undecided → Critical |
status: | New → In Progress |
summary: |
- Latest apt returns Hash Sum mismatch for file: URI:s + Regression: Latest apt security update returns Hash Sum mismatch for + file: URI:s |
Changed in apt (Debian): | |
status: | Unknown → New |
tags: | added: patch |
Changed in apt (Ubuntu Lucid): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in apt (Ubuntu Precise): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in apt (Ubuntu Trusty): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in apt (Ubuntu Trusty): | |
status: | Confirmed → Fix Released |
Changed in apt (Debian): | |
status: | New → Fix Released |
tags: | added: lucid regression-update |
tags: | added: amd64 |
information type: | Public → Public Security |
Note that this also fixes a segfault due to a broken FileFD: :ReadOnlyGzip in this particular apt version.