{"id":"UBUNTU-CVE-2017-7443","details":"apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression.","modified":"2025-10-24T04:46:14Z","published":"2017-04-05T20:59:00Z","upstream":["CVE-2017-7443"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-7443"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2017-7443"}],"affected":[{"package":{"name":"apt-cacher","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/apt-cacher@1.7.11?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.7.11"],"ecosystem_specific":{"binaries":[{"binary_name":"apt-cacher","binary_version":"1.7.11"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-7443.json"}},{"package":{"name":"apt-cacher-ng","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/apt-cacher-ng@0.9.1-1ubuntu1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.5-1","0.8.6-1","0.8.7-1","0.8.8-1","0.8.9-1","0.8.9-1ubuntu1","0.9.1-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"apt-cacher-ng","binary_version":"0.9.1-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-7443.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"low"}]}