First published: Sat Mar 25 2017(Updated: )
apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apt-cacher-ng Project Apt-cacher-ng | <=3.3 | |
Apt-cacher Project Apt-cacher | <=1.7.13 | |
debian/apt-cacher | 1.7.22 1.7.29 1.7.30 | |
debian/apt-cacher-ng | 3.6.4-1 3.7.4-1 3.7.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.