CVE-2020-5202
published 2020-01-21CVE-2020-5202: apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.46%
37.7th percentile
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-ng (which is active by default) attempts this periodically. Because 3142 is an unprivileged port, any local user can try to bind to this port and will receive requests from acngtool. There can be sensitive data in these requests, e.g., if AdminAuth is enabled in /etc/apt-cacher-ng/security.conf. This sensitive data can leak to unprivileged local users that manage to bind to this port before the apt-cacher-ng daemon can.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apt-cacher-ng_project | apt-cacher-ng | <= 3.3 | — |
| apt-cacher-ng_project | apt-cacher-ng | >= 0 < 3.3.1-1 | 3.3.1-1 |
| apt-cacher-ng_project | apt-cacher-ng | >= 0 < 3.3.1-1 | 3.3.1-1 |
| apt-cacher-ng_project | apt-cacher-ng | >= 0 < 3.3.1-1 | 3.3.1-1 |
| apt-cacher-ng_project | apt-cacher-ng | >= 0 < 3.3.1-1 | 3.3.1-1 |
| debian | apt-cacher-ng | < apt-cacher-ng 3.3.1-1 (bookworm) | apt-cacher-ng 3.3.1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| opensuse | backports | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ppjv-mwcc-539j: apt-cacher-ng through 3
ghsa_unreviewed·2022-05-24
CVE-2020-5202 [LOW] CWE-200 GHSA-ppjv-mwcc-539j: apt-cacher-ng through 3
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-ng (which is active by default) attempts this periodically. Because 3142 is an unprivileged port, any local user can try to bind to this port and will receive requests from acngtool. There can be sensitive data in these requests, e.g., if AdminAuth is enabled in /etc/apt-cacher-ng/security.conf. This sensitive data can leak to unprivileged local users that manage to bind to this port before the apt-cacher-ng daemon can.
OSV
CVE-2020-5202: apt-cacher-ng through 3
osv·2020-01-21·CVSS 5.5
CVE-2020-5202 [MEDIUM] CVE-2020-5202: apt-cacher-ng through 3
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-ng (which is active by default) attempts this periodically. Because 3142 is an unprivileged port, any local user can try to bind to this port and will receive requests from acngtool. There can be sensitive data in these requests, e.g., if AdminAuth is enabled in /etc/apt-cacher-ng/security.conf. This sensitive data can leak to unprivileged local users that manage to bind to this port before the apt-cacher-ng daemon can.
Debian
CVE-2020-5202: apt-cacher-ng - apt-cacher-ng through 3.3 allows local users to obtain sensitive information by ...
vendor_debian·2020·CVSS 5.5
CVE-2020-5202 [MEDIUM] CVE-2020-5202: apt-cacher-ng - apt-cacher-ng through 3.3 allows local users to obtain sensitive information by ...
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-ng (which is active by default) attempts this periodically. Because 3142 is an unprivileged port, any local user can try to bind to this port and will receive requests from acngtool. There can be sensitive data in these requests, e.g., if AdminAuth is enabled in /etc/apt-cacher-ng/security.conf. This sensitive data can leak to unprivileged local users that manage to bind to this port before the apt-cacher-ng daemon can.
Scope: local
boo
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-5202 apt-cacher-ng: local unprivileged user can impersonate the apt-cacher-ng daemon leading to credentials leak
bugzilla·2020-03-16·CVSS 5.5
CVE-2020-5202 [MEDIUM] CVE-2020-5202 apt-cacher-ng: local unprivileged user can impersonate the apt-cacher-ng daemon leading to credentials leak
CVE-2020-5202 apt-cacher-ng: local unprivileged user can impersonate the apt-cacher-ng daemon leading to credentials leak
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit SocketPath=/var/run/apt-cacher-ng/socket command-line option is passed. The cron job /etc/cron.daily/apt-cacher-ng (which is active by default) attempts this periodically. Because 3142 is an unprivileged port, any local user can try to bind to this port and will receive requests from acngtool. There can be sensitive data in these requests, e.g., if AdminAuth is enabled in /etc/apt-cacher-ng/security.conf. This sensitive data
Bugzilla
CVE-2020-5202 apt-cacher-ng: local unprivileged user can impersonate the apt-cacher-ng daemon leading to credentials leak [fedora-all]
bugzilla·2020-03-16·CVSS 5.5
CVE-2020-5202 [MEDIUM] CVE-2020-5202 apt-cacher-ng: local unprivileged user can impersonate the apt-cacher-ng daemon leading to credentials leak [fedora-all]
CVE-2020-5202 apt-cacher-ng: local unprivileged user can impersonate the apt-cacher-ng daemon leading to credentials leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2020-5202 apt-cacher-ng: local unprivileged user can impersonate the apt-cacher-ng daemon leading to credentials leak [epel-7]
bugzilla·2020-03-16·CVSS 5.5
CVE-2020-5202 [MEDIUM] CVE-2020-5202 apt-cacher-ng: local unprivileged user can impersonate the apt-cacher-ng daemon leading to credentials leak [epel-7]
CVE-2020-5202 apt-cacher-ng: local unprivileged user can impersonate the apt-cacher-ng daemon leading to credentials leak [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Di
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00057.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00065.htmlhttp://www.openwall.com/lists/oss-security/2020/01/20/4http://www.openwall.com/lists/oss-security/2020/01/20/4https://seclists.org/oss-sec/2020/q1/21https://security-tracker.debian.org/tracker/CVE-2020-5202http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00057.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00065.htmlhttp://www.openwall.com/lists/oss-security/2020/01/20/4http://www.openwall.com/lists/oss-security/2020/01/20/4https://seclists.org/oss-sec/2020/q1/21https://security-tracker.debian.org/tracker/CVE-2020-5202
2020-01-21
Published