CVE-2019-3462

HIGH

advanced_package_tool <= 1.4.8 - Remote Code Execution via HTTP Redirect Field Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-3462. PoCs published by tonejito, atilacastro.

AI-analyzed exploit summary This repository contains a bash script to check if a Debian or Ubuntu system is vulnerable to CVE-2019-3462, a vulnerability in APT. The script compares the installed APT version against known vulnerable versions for specific OS releases.

Description

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

Exploits (2)

nomisec SCANNER 2 stars
by tonejito · poc
https://github.com/tonejito/check_CVE-2019-3462

This repository contains a bash script to check if a Debian or Ubuntu system is vulnerable to CVE-2019-3462, a vulnerability in APT. The script compares the installed APT version against known vulnerable versions for specific OS releases.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: APT (Advanced Package Tool) on Debian and Ubuntu
No auth needed
Prerequisites: Access to the target system's command line · APT installed on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB
by atilacastro · poc
https://github.com/atilacastro/update-apt-package

The repository contains only a README.md file with minimal content, which appears to be a placeholder or stub. No functional exploit code or technical details are provided.

Classification
Stub 10%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106690
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3863-1/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3863-2/
Mailing List, Vendor Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/01/msg00013.html
Patch, Vendor Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4371
Mailing List, Vendor Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/01/msg00014.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190125-0002/

Scores

CVSS v3 8.1
EPSS 0.0699
EPSS Percentile 91.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (10)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
debian/advanced_package_tool < 1.2.30
debian/debian_linux 8.0
debian/debian_linux 9.0
netapp/active_iq
netapp/element_software
Published Jan 28, 2019
Tracked Since Feb 18, 2026