Sensitive Information Disclosure in apt-cacher-ng Affected by Local User Exploit
CVE-2020-5202

5.5MEDIUM

Key Information:

Vendor
CVE Published:
21 January 2020

What is CVE-2020-5202?

The apt-cacher-ng product is vulnerable due to its handling of TCP connections on an unprivileged port. Local users can exploit this by binding to the hardcoded TCP port 3142 used by the acngtool program. Despite attempts to specify an alternative SocketPath, the program still defaults to using localhost on port 3142. This flaw allows unprivileged local users to receive requests from acngtool, potentially exposing sensitive information, especially if authentication is enabled. The active cron job further complicates the issue, as it periodically attempts to connect to the daemon, increasing the risk of data leakage.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.