PT-2019-1258 · Debian+1 · Apt+1

Max Justicz

·

Publicado

2019-01-22

·

Atualizado

2020-08-24

·

CVE-2019-3462

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions apt versions 1.4.8 and earlier
Description The issue is related to incorrect sanitation of the 302 redirect field in the HTTP transport method, which can lead to content injection by a Man-In-The-Middle (MITM) attacker. This potentially allows for remote code execution on the target machine.
Recommendations For apt versions 1.4.8 and earlier, update to a version later than 1.4.8 to resolve the issue. As a temporary workaround, consider restricting the use of the HTTP transport method until a patch is available. Avoid using the HTTP protocol in apt configurations to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00415
CVE-2019-3462
DLA-1637-1
DSA-4371-1
USN-3863-1
USN-3863-2

Produtos afetados

Ubuntu
Apt