PT-2019-1258 · Debian+1 · Apt+1

Max Justicz

·

Published

2019-01-22

·

Updated

2020-08-24

·

CVE-2019-3462

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions apt versions 1.4.8 and earlier
Description The issue is related to incorrect sanitation of the 302 redirect field in the HTTP transport method, which can lead to content injection by a Man-In-The-Middle (MITM) attacker. This potentially allows for remote code execution on the target machine.
Recommendations For apt versions 1.4.8 and earlier, update to a version later than 1.4.8 to resolve the issue. As a temporary workaround, consider restricting the use of the HTTP transport method until a patch is available. Avoid using the HTTP protocol in apt configurations to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00415
CVE-2019-3462
DLA-1637-1
DSA-4371-1
USN-3863-1
USN-3863-2

Affected Products

Ubuntu
Apt