CVE Published: 28/01/2019 |
CVE Updated: 16/09/2024 |
CVE Year: 2019 Source: debian |
Vendor: Debian GNU/Linux |
Product: apt as used in Debian Stretch and Ubuntu Status : PUBLISHED
CVE-2019-3462 Description
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.