CVE-2019-3462
published 2019-01-28CVE-2019-3462: Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker…
PriorityP355high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
14.56%
96.3th percentile
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | advanced_package_tool | < 1.2.30 | 1.2.30 |
| debian | advanced_package_tool | 1.3 – 1.4.8 | — |
| debian | apt | < apt 1.8.0~alpha3.1 (bookworm) | apt 1.8.0~alpha3.1 (bookworm) |
| debian | apt | >= 0 < 1.8.0~alpha3.1 | 1.8.0~alpha3.1 |
| debian | apt | >= 0 < 1.8.0~alpha3.1 | 1.8.0~alpha3.1 |
| debian | apt | >= 0 < 1.8.0~alpha3.1 | 1.8.0~alpha3.1 |
| debian | apt | >= 0 < 1.8.0~alpha3.1 | 1.8.0~alpha3.1 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| github.com | weaveworks_weave | >= 0 < 2.6.3 | 2.6.3 |
| weave | weave_net | < 2.6.3 | 2.6.3 |
| weaveworks | weave | < 2.6.3 | 2.6.3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
ghsa8.1HIGH
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q857-rhg5-4j49: Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1
ghsa_unreviewed·2022-05-13
CVE-2019-3462 [HIGH] GHSA-q857-rhg5-4j49: Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
OSV
Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
osv·2021-05-27·CVSS 8.1
CVE-2020-11091 [HIGH] Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
### Impact
An attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service.
In a cluster with an IPv4 internal network, if IPv6 is not totally disabled on the host (via ipv6.disable=1 on the kernel cmdline), it will be either unconfigured or configured on some interfaces, but it’s pretty likely that ipv6 forwarding is disabled, ie /proc/sys/net/ipv6/conf//forwarding == 0. Also by default, /proc/sys/net/ipv6/conf//accept_ra == 1. The combination of these 2 sysctls means that the host accepts router advertisements and configure the IPv6 stack using them.
By sending “rogue” router advertisements, an attacker can reconf
GHSA
Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
ghsa·2021-05-27·CVSS 8.1
CVE-2020-11091 [HIGH] CWE-350 Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
### Impact
An attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service.
In a cluster with an IPv4 internal network, if IPv6 is not totally disabled on the host (via ipv6.disable=1 on the kernel cmdline), it will be either unconfigured or configured on some interfaces, but it’s pretty likely that ipv6 forwarding is disabled, ie /proc/sys/net/ipv6/conf//forwarding == 0. Also by default, /proc/sys/net/ipv6/conf//accept_ra == 1. The combination of these 2 sysctls means that the host accepts router advertisements and configure the IPv6 stack using them.
By sending “rogue” router advertisements, an attacker can reconf
OSV
CVE-2019-3462: Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1
osv·2019-01-28·CVSS 8.1
CVE-2019-3462 [HIGH] CVE-2019-3462: Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
Ubuntu
APT vulnerability
vendor_ubuntu·2019-01-22
CVE-2019-3462 APT vulnerability
Title: APT vulnerability
Summary: An attacker could trick APT into installing altered packages.
Max Justicz discovered that APT incorrectly handled certain parameters
during redirects. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could potentially be used to install
altered packages.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
APT vulnerability
vendor_ubuntu·2019-01-22
CVE-2019-3462 APT vulnerability
Title: APT vulnerability
Summary: An attacker could trick APT into installing altered packages.
USN-3863-1 fixed a vulnerability in APT. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Max Justicz discovered that APT incorrectly handled certain parameters
during redirects. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could potentially be used to install
altered packages.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-3462: apt - Incorrect sanitation of the 302 redirect field in HTTP transport method of apt v...
vendor_debian·2019·CVSS 8.1
CVE-2019-3462 [HIGH] CVE-2019-3462: apt - Incorrect sanitation of the 302 redirect field in HTTP transport method of apt v...
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
Scope: local
bookworm: resolved (fixed in 1.8.0~alpha3.1)
bullseye: resolved (fixed in 1.8.0~alpha3.1)
forky: resolved (fixed in 1.8.0~alpha3.1)
sid: resolved (fixed in 1.8.0~alpha3.1)
trixie: resolved (fixed in 1.8.0~alpha3.1)
No detection rules found.
No public exploits indexed.
HackerOne
IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
hackerone·2021-11-07·CVSS 8.1
CVE-2019-9946 [HIGH] IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
This bug report mostly concerns the default CNI plugins (https://github.com/containernetworking/plugins) but I believe affects many K8S clusters.
Because the CNI team still doesn’t provide an explicit way to report security bugs, I hope the K8S security team doesn’t mind doing the coordination job again as was done for CVE-2019-9946.
I understand this is out of scope for this bounty, and I understand if you want to close this report and prefer that I resend it via email to [email protected] or other.
## Summary:
In many K8S network configurations the container network interface is a virtual ethernet link going to the host (veth interface). In this configuration, an attacker able to run a process as r
Bugzilla
CVE-2019-3462 apt: Code injection through HTTP redirect
bugzilla·2019-01-23·CVSS 8.1
CVE-2019-3462 [HIGH] CVE-2019-3462 apt: Code injection through HTTP redirect
CVE-2019-3462 apt: Code injection through HTTP redirect
The code handling HTTP redirects in the HTTP transport method doesn't properly
sanitize fields transmitted over the wire. This vulnerability could be used by
an attacker located as a man-in-the-middle between APT and a mirror to inject
malicous content in the HTTP connection. This content could then be recognized
as a valid package by APT and used later for code execution with root
privileges on the target machine.
External references:
https://justi.cz/security/2019/01/22/apt-rce.html
Discussion:
Created apt tracking bugs for this issue:
Affects: fedora-all [bug 1668759]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product.
Bugzilla
CVE-2019-3462 apt: Code injection through HTTP redirect [fedora-all]
bugzilla·2019-01-23·CVSS 8.1
CVE-2019-3462 [HIGH] CVE-2019-3462 apt: Code injection through HTTP redirect [fedora-all]
CVE-2019-3462 apt: Code injection through HTTP redirect [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
arXiv
An Analysis of Security Vulnerabilities in Container Images for Scientific Data Analysis
arxiv_fulltext·2021-03-17
An Analysis of Security Vulnerabilities in Container Images for Scientific Data Analysis
Bhupinder Kaur, Mathieu Dugr\'e, Aiman Hanna, Tristan Glatard \ of Computer Science and Software Engineering
Concordia University
Montreal, Canada
## Abstract
Software containers greatly facilitate the deployment and reproducibility
of scientific data analyses in various platforms. However,
container images often contain outdated or unnecessary software packages,
which increases the number of security vulnerabilities in the images,
widens the attack surface in the container host, and creates
substantial security risks for computing infrastructures at large. This paper
presents a vulnerability analysis of container images for scientific data
analysis. We compare results obtained with four vulnerability scanners,
focusing on the use case of neuroscience data analysis, and quantifying the
e
http://www.securityfocus.com/bid/106690https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/01/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2019/01/msg00014.htmlhttps://security.netapp.com/advisory/ntap-20190125-0002/https://usn.ubuntu.com/3863-1/https://usn.ubuntu.com/3863-2/https://www.debian.org/security/2019/dsa-4371http://www.securityfocus.com/bid/106690https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/01/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2019/01/msg00014.htmlhttps://security.netapp.com/advisory/ntap-20190125-0002/https://usn.ubuntu.com/3863-1/https://usn.ubuntu.com/3863-2/https://www.debian.org/security/2019/dsa-4371
2019-01-28
Published