CVE-2020-27350
published 2020-12-10CVE-2020-27350: APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc…
PriorityP423medium5.7CVSS 3.1
AVLACLPRHUINSCCLILAL
EPSS
0.38%
29.8th percentile
APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | apt | >= 1.2.32ubuntu0 < 1.2.32ubuntu0.2 | 1.2.32ubuntu0.2 |
| canonical | apt | >= 1.6.12ubuntu0 < 1.6.12ubuntu0.2 | 1.6.12ubuntu0.2 |
| canonical | apt | >= 2.0.2ubuntu0 < 2.0.2ubuntu0.2 | 2.0.2ubuntu0.2 |
| canonical | apt | >= 2.1.10ubuntu0 < 2.1.10ubuntu0.1 | 2.1.10ubuntu0.1 |
| debian | advanced_package_tool | < 1.8.2.2 | 1.8.2.2 |
| debian | advanced_package_tool | >= 1.2.32ubuntu0 < 1.2.32ubuntu0.2 | 1.2.32ubuntu0.2 |
| debian | advanced_package_tool | >= 1.6.12ubuntu0 < 1.6.12ubuntu0.2 | 1.6.12ubuntu0.2 |
| debian | advanced_package_tool | >= 2.0.2ubuntu0 < 2.0.2ubuntu0.2 | 2.0.2ubuntu0.2 |
| debian | advanced_package_tool | >= 2.1.10ubuntu0 < 2.1.10ubuntu0.2 | 2.1.10ubuntu0.2 |
| debian | apt | < apt 2.1.13 (bookworm) | apt 2.1.13 (bookworm) |
| debian | apt | >= 0 < 2.1.13 | 2.1.13 |
| debian | apt | >= 0 < 2.1.13 | 2.1.13 |
| debian | apt | >= 0 < 2.1.13 | 2.1.13 |
| debian | apt | >= 0 < 2.1.13 | 2.1.13 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv5.7MEDIUM
vendor_debian5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
APT vulnerability
vendor_ubuntu·2021-01-11
CVE-2020-27350 APT vulnerability
Title: APT vulnerability
Summary: APT could be made to crash or stop responding if it opened a specially
crafted file.
USN-4667-1 fixed a vulnerability in APT. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Kevin Backhouse discovered that APT incorrectly handled certain packages.
A local attacker could possibly use this issue to cause APT to crash or
stop responding, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
APT vulnerability
vendor_ubuntu·2020-12-09
CVE-2020-27350 APT vulnerability
Title: APT vulnerability
Summary: APT could be made to crash or stop responding if it opened a specially
crafted file.
Kevin Backhouse discovered that APT incorrectly handled certain packages.
A local attacker could possibly use this issue to cause APT to crash or
stop responding, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-27350: apt - APT had several integer overflows and underflows while parsing .deb packages, ak...
vendor_debian·2020·CVSS 5.7
CVE-2020-27350 [MEDIUM] CVE-2020-27350: apt - APT had several integer overflows and underflows while parsing .deb packages, ak...
APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;
Scope: local
bookworm: resolved (fixed in 2.1.13)
bullseye: resolved (fixed in 2.1.13)
forky: resolved (fixed in 2.1.13)
sid: resolved (fixed in 2.1.13)
trixie: resolved (fixed in 2.1.13)
GHSA
GHSA-j2wg-wfjw-m5cq: APT had several integer overflows and underflows while parsing
ghsa_unreviewed·2022-05-24
CVE-2020-27350 [MEDIUM] CWE-190 GHSA-j2wg-wfjw-m5cq: APT had several integer overflows and underflows while parsing
APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;
OSV
CVE-2020-27350: APT had several integer overflows and underflows while parsing
osv·2020-12-10·CVSS 5.7
CVE-2020-27350 [MEDIUM] CVE-2020-27350: APT had several integer overflows and underflows while parsing
APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.launchpad.net/bugs/1899193https://security.netapp.com/advisory/ntap-20210108-0005/https://usn.ubuntu.com/usn/usn-4667-1https://www.debian.org/security/2020/dsa-4808https://bugs.launchpad.net/bugs/1899193https://security.netapp.com/advisory/ntap-20210108-0005/https://usn.ubuntu.com/usn/usn-4667-1https://www.debian.org/security/2020/dsa-4808
2020-12-10
Published