Sensitive Information Disclosure in apt-cacher-ng Affected by Local User Exploit
CVE-2020-5202
What is CVE-2020-5202?
The apt-cacher-ng product is vulnerable due to its handling of TCP connections on an unprivileged port. Local users can exploit this by binding to the hardcoded TCP port 3142 used by the acngtool program. Despite attempts to specify an alternative SocketPath, the program still defaults to using localhost on port 3142. This flaw allows unprivileged local users to receive requests from acngtool, potentially exposing sensitive information, especially if authentication is enabled. The active cron job further complicates the issue, as it periodically attempts to connect to the daemon, increasing the risk of data leakage.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
