APT(Advanced Packaging Tool)是一套基于Debian系统及其派生发行版的强大的包管理工具。该工具可自动下载、配置、安装二进制或源代码格式的软件包。apt-get是其中的一个用于搜索、安装、升级和卸载程序的组件。 APT 1.4.8及之前版本中的apt-get存在远程代码执行漏洞,该漏洞源于程序没有正确地过滤字段。远程攻击者可通过实施中间人攻击利用该漏洞执行任意代码/命令并可能获取目标服务器的root权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Debian GNU/Linux | apt as used in Debian Stretch and Ubuntu | 1.4.8 and earlier | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Check @Debian and @Ubuntu #GNU / #Linux for CVE-2019-3462 in APT | https://github.com/tonejito/check_CVE-2019-3462 | POC Details |
| 2 | Playbook update APT package because CVE-2019-3462 | https://github.com/atilacastro/update-apt-package | POC Details |
No public POC found.
Login to generate AI POCNo comments yet