CVE-2019-3462

HIGH8.1EPSS 12.7%

apt - security update

發布日:2019/1/28修改日:2026/3/9
也稱為:DSA-4371-1DEBIAN-CVE-2019-3462DLA-1637-1

描述

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(1)