CVE-2017-7443: Medium severity Apt-cacher-ng Project Apt-cacher-ng vulnerability
apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apt-cacherto a version that resolves this vulnerability.Fixed in 1.7.22Fixed in 1.7.29Fixed in 1.7.30 - Upgrade
Upgrade
debian/apt-cacher-ngto a version that resolves this vulnerability.Fixed in 3.6.4-1Fixed in 3.7.4-1Fixed in 3.7.5-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7443?
CVE-2017-7443 is classified as a medium severity vulnerability due to its potential impact on HTTP response splitting.
How do I fix CVE-2017-7443?
To resolve CVE-2017-7443, update apt-cacher to version 1.7.22 or higher, or apt-cacher-ng to version 3.6.4-1 or higher.
What software versions are affected by CVE-2017-7443?
CVE-2017-7443 affects apt-cacher versions below 1.7.15 and apt-cacher-ng versions below 3.4.
Can CVE-2017-7443 allow for remote attacks?
Yes, CVE-2017-7443 can allow attackers to exploit HTTP response splitting which may lead to further attacks.
Is CVE-2017-7443 exploitable on all platforms?
CVE-2017-7443 is exploitable specifically in environments using the affected versions of apt-cacher and apt-cacher-ng.