CVE-2019-3462

HIGH8.1EPSS 12.7%

apt - security update

Published: 1/28/2019Modified: 3/9/2026
Also known as:DSA-4371-1DEBIAN-CVE-2019-3462DLA-1637-1

Description

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References (1)