Independent security consultant Max Justicz has discovered a remote code execution vulnerability in the APT package manager used by several Linux distributions, including Debian and Ubuntu. The flaw, tracked as CVE-2019-3462, affects package manager version 0.8.15 and later, it could be exploited by an attacker in a MiTM position to execute arbitrary code as root on a machine and install any package. The vulnerability could affect all package downloads, including packages installed by the user for the first time.”]
Source: https://securityaffairs.co/wordpress/80188/hacking/linux-apt-package-manage-flaw.html

