DEBIAN-CVE-2017-7443

Source
https://security-tracker.debian.org/tracker/CVE-2017-7443
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-7443.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2017-7443
Upstream
Downstream
Published
2017-04-05T20:59:00.400Z
Modified
2025-11-19T01:08:48.365113Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression.

References

Affected packages

Debian:11
apt-cacher

Package

Name
apt-cacher
Purl
pkg:deb/debian/apt-cacher?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.15

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-7443.json"
apt-cacher-ng

Package

Name
apt-cacher-ng
Purl
pkg:deb/debian/apt-cacher-ng?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-7443.json"
Debian:12
apt-cacher

Package

Name
apt-cacher
Purl
pkg:deb/debian/apt-cacher?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.15

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-7443.json"
apt-cacher-ng

Package

Name
apt-cacher-ng
Purl
pkg:deb/debian/apt-cacher-ng?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-7443.json"
Debian:13
apt-cacher

Package

Name
apt-cacher
Purl
pkg:deb/debian/apt-cacher?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.15

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-7443.json"
apt-cacher-ng

Package

Name
apt-cacher-ng
Purl
pkg:deb/debian/apt-cacher-ng?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-7443.json"
Debian:14
apt-cacher

Package

Name
apt-cacher
Purl
pkg:deb/debian/apt-cacher?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.15

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-7443.json"
apt-cacher-ng

Package

Name
apt-cacher-ng
Purl
pkg:deb/debian/apt-cacher-ng?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-7443.json"