CVE-2019-3462Patch(canonical / active_iq)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch canonical active_iq systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

1.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_iq
  • advanced_package_tool
  • debian_linux
  • element_software

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
active_iqadvanced_package_tooldebian_linuxelement_softwareubuntu_linux

8 versions affected across 5 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-05: 1Patch / Workaround · 2026-05-05: 105-05
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • autumn@4utum00n
    Patch

    ふとdockerでapt-getしたときにhttpスキームで通信してるのが気になって、なんか出来そうだなって調べてみたら7年前に潰されてる脆弱性(CVE-2019-3462)だった そりゃそうかと思いつつ、今の今まで気にしたことなかったなと自省

    Post summary

    The user discovered CVE‑2019‑3462 while inspecting HTTP usage in Docker and noted it had been patched seven years ago, indicating no current concern.

    00000114
    307 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux12.04--
OScanonicalubuntu_linux14.04--
OScanonicalubuntu_linux16.04--
OScanonicalubuntu_linux18.04--
OScanonicalubuntu_linux18.10--
Appdebianadvanced_package_tool---
OSdebiandebian_linux8.0--
OSdebiandebian_linux9.0--
Appnetappactive_iq---
Appnetappelement_software---

Explore more