summaryrefslogtreecommitdiff
path: root/test/libapt/openmaybeclearsignedfile_test.cc
diff options
context:
space:
mode:
authorJulian Andres Klode <julian.klode@canonical.com>2019-01-18 09:13:52 +0100
committerJulian Andres Klode <julian.klode@canonical.com>2019-01-25 12:38:22 +0100
commit89dca2f0fbfe07bca50e7f2a43c88e2c17d763b5 (patch)
tree0942bc1a41549bebbe0c8e56035949d960a1da79 /test/libapt/openmaybeclearsignedfile_test.cc
parent49383c24a8eeab8483b10d883f91d96633e2da76 (diff)
SECURITY UPDATE: content injection in http method (CVE-2019-3462)
This fixes a security issue that can be exploited to inject arbritrary debs or other files into a signed repository as followed: (1) Server sends a redirect to somewhere%0a<headers for the apt method> (where %0a is \n encoded) (2) apt method decodes the redirect (because the method encodes the URLs before sending them out), writting something like somewhere\n <headers> into its output (3) apt then uses the headers injected for validation purposes. Regression-Of: c34ea12ad509cb34c954ed574a301c3cbede55ec LP: #1812353
Diffstat (limited to 'test/libapt/openmaybeclearsignedfile_test.cc')
0 files changed, 0 insertions, 0 deletions