CVE-2019-3462: Critical severity Debian Advanced Package Tool vulnerability
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-3462?
CVE-2019-3462 is a vulnerability in the HTTP transport method of apt versions 1.4.8 and earlier, which allows a MITM attacker to inject content and potentially execute remote code on the target machine.
How does CVE-2019-3462 affect Debian's Advanced Package Tool (APT)?
CVE-2019-3462 affects APT versions 1.4.8 and earlier in Debian, potentially leading to content injection and remote code execution.
Which versions of Ubuntu Linux are affected by CVE-2019-3462?
CVE-2019-3462 affects Ubuntu Linux versions 12.04, 14.04, 16.04, 18.04, and 18.10.
What is the severity of CVE-2019-3462?
CVE-2019-3462 has a severity rating of 8.1 (critical).
Where can I find more information about CVE-2019-3462?
You can find more information about CVE-2019-3462 at the following references: [Link 1](https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1812353), [Link 2](https://justi.cz/security/2019/01/22/apt-rce.html), [Link 3](https://security-tracker.debian.org/tracker/CVE-2019-3462)