CVE Vulnerabilities

CVE-2019-3462

Published: Jan 28, 2019 | Modified: Nov 07, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
HIGH

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

Affected Software

Name Vendor Start Version End Version
Advanced_package_tool Debian * 1.2.30 (excluding)
Advanced_package_tool Debian 1.3 (including) 1.4.8 (including)
Apt Ubuntu bionic *
Apt Ubuntu cosmic *
Apt Ubuntu devel *
Apt Ubuntu trusty *
Apt Ubuntu xenial *

References