Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3462

Опубликовано: 28 янв. 2019
Источник: debian

Описание

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
aptfixed1.8.0~alpha3.1package

Примечания

  • https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1812353

  • https://justi.cz/security/2019/01/22/apt-rce.html

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 7 лет назад

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

CVSS3: 8.1
nvd
около 7 лет назад

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

CVSS3: 8.1
github
больше 3 лет назад

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

CVSS3: 7.5
fstec
около 7 лет назад

Уязвимость в программном обеспечении apt, связанная с неправильной очисткой поля перенаправления, позволяющая нарушителю выполнить удаленный код на целевой машине