CVE-2017-7443 (NVD)

2017-04-05

apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression.

Products Apt\-Cacher\-Ng, Apt\-Cacher
Type Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') (CWE-113)
First patch - None (likely due to unavailable code)
Links https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858833
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858739