Some popular Linux have a bug in their package-management interface that an attacker could exploit to trick the user into installing a malicious package. This would then give the attacker access to the target machine.
The flaw is located in the APT package manager, which handles how software packages are downloaded and installed on Linux systems, such as Debian and Ubuntu. Researcher Max Justicz discovered a flaw in APT, involving the way the program handles redirects during the installation process, which an attacker could exploit to gain access to a victim's machine.
Many versions of Debian and Ubuntu are vulnerable to this bug and the administrators of both distributions have released updates that fix the problem. Ubuntu 18.10, Ubuntu 18.04 LTS, Ubuntu 16.04 LTS and Ubuntu 14.04 LTS are all vulnerable. Debian 1.4.9 is the patch version for this distribution.
The vulnerable versions of APT do not “clean” certain parameters correctly during HTTP redirects. An attacker can exploit this and execute a remote man-in-the-middle attack to install malicious content, thereby deceiving the system to install some altered packages.
“This content could be recognized as a valid package by APT and later used for code execution on the target computer.
Justicz mentioned a technique that an intruder could use for a man-in-the-middle attack to install a malicious package on a vulnerable Debian system. The method is based on the fact that a specific file is installed in a known location.
One of the fundamental problems that the exploitation of this flaw allows is that update servers provide packages via HTTP and not HTTPS. Even though the packages are legitimate, an attacker could use the flaw to place a malicious package on the victim's computer. Justicz recommended that administrators use HTTPS by default to protect themselves from these attacks.
“HTTP support is good. I just think it’s worth making HTTPS the default – the more secure default – and allowing users to downgrade their security later if they choose”.
