CVE-2019-3462
HIGHadvanced_package_tool <= 1.4.8 - Remote Code Execution via HTTP Redirect Field Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2019-3462. PoCs published by tonejito, atilacastro.
AI-analyzed exploit summary This repository contains a bash script to check if a Debian or Ubuntu system is vulnerable to CVE-2019-3462, a vulnerability in APT. The script compares the installed APT version against known vulnerable versions for specific OS releases.
Description
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
Exploits (2)
This repository contains a bash script to check if a Debian or Ubuntu system is vulnerable to CVE-2019-3462, a vulnerability in APT. The script compares the installed APT version against known vulnerable versions for specific OS releases.
The repository contains only a README.md file with minimal content, which appears to be a placeholder or stub. No functional exploit code or technical details are provided.
References (8)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H