cbcvebase.
CVE-2019-3462
published 2019-01-28

CVE-2019-3462: Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker…

high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianadvanced_package_tool< 1.2.301.2.30
debianadvanced_package_tool1.3 – 1.4.8
debianapt< apt 1.8.0~alpha3.1 (bookworm)apt 1.8.0~alpha3.1 (bookworm)
debianapt>= 0 < 1.8.0~alpha3.11.8.0~alpha3.1
debianapt>= 0 < 1.8.0~alpha3.11.8.0~alpha3.1
debianapt>= 0 < 1.8.0~alpha3.11.8.0~alpha3.1
debianapt>= 0 < 1.8.0~alpha3.11.8.0~alpha3.1
debiandebian_linux
debiandebian_linux
github.comweaveworks_weave>= 0 < 2.6.32.6.3
weaveweave_net< 2.6.32.6.3
weaveworksweave< 2.6.32.6.3

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.1HIGH
osv8.1HIGH