CVE-2020-27351
published 2020-12-10CVE-2020-27351: Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue…
PriorityP410low2.8CVSS 3.1
AVLACLPRLUIRSUCNINAL
EPSS
0.39%
31.1th percentile
Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | python-apt | >= 0 < 2.1.7 | 2.1.7 |
| canonical | python-apt | >= 0 < 2.1.7 | 2.1.7 |
| canonical | python-apt | >= 0 < 2.1.7 | 2.1.7 |
| canonical | python-apt | >= 0 < 2.1.7 | 2.1.7 |
| canonical | python-apt | >= 1.1.0~beta1 < 1.1.0~beta1ubuntu0.16.04.10 | 1.1.0~beta1ubuntu0.16.04.10 |
| canonical | python-apt | >= 1.6.5ubuntu0 < 1.6.5ubuntu0.4 | 1.6.5ubuntu0.4 |
| canonical | python-apt | >= 2.0.0ubuntu0 < 2.0.0ubuntu0.20.04.2 | 2.0.0ubuntu0.20.04.2 |
| canonical | python-apt | >= 2.1.3ubuntu1 < 2.1.3ubuntu1.1 | 2.1.3ubuntu1.1 |
| debian | advanced_package_tool | < 1.8.4.2 | 1.8.4.2 |
| debian | advanced_package_tool | >= 1.1.0\~beta1 < 1.1.0\~beta1ubuntu0.16.04.10 | 1.1.0\~beta1ubuntu0.16.04.10 |
| debian | advanced_package_tool | >= 1.6.5ubuntu0 < 1.6.5ubuntu0.4 | 1.6.5ubuntu0.4 |
| debian | advanced_package_tool | >= 2.0.0ubuntu0 < 2.0.0ubuntu0.20.04.2 | 2.0.0ubuntu0.20.04.2 |
| debian | advanced_package_tool | >= 2.1.3ubuntu1 < 2.1.30ubuntu1.1 | 2.1.30ubuntu1.1 |
| debian | python-apt | < python-apt 2.1.7 (bookworm) | python-apt 2.1.7 (bookworm) |
CVSS provenance
nvdv3.12.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.8LOW
vendor_debian2.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
python-apt vulnerability
vendor_ubuntu·2021-01-11
CVE-2020-27351 python-apt vulnerability
Title: python-apt vulnerability
Summary: python-apt could be made to crash if it opened a specially crafted file.
USN-4668-1 fixed a vulnerability in python-apt. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Kevin Backhouse discovered that python-apt incorrectly handled resources. A
local attacker could possibly use this issue to cause python-apt to consume
resources, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
python-apt vulnerability
vendor_ubuntu·2020-12-09
CVE-2020-27351 python-apt vulnerability
Title: python-apt vulnerability
Summary: python-apt could be made to crash if it opened a specially crafted file.
Kevin Backhouse discovered that python-apt incorrectly handled resources. A
local attacker could possibly use this issue to cause python-apt to consume
resources, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-27351: python-apt - Various memory and file descriptor leaks were found in apt-python files python/a...
vendor_debian·2020·CVSS 2.0
CVE-2020-27351 [LOW] CVE-2020-27351: python-apt - Various memory and file descriptor leaks were found in apt-python files python/a...
Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;
Scope: local
bookworm: resolved (fixed in 2.1.7)
bullseye: resolved (fixed in 2.1.7)
forky: resolved (fixed in 2.1.7)
sid: resolved (fixed in 2.1.7)
trixie: resolved (fixed in 2.1.7)
GHSA
GHSA-mfw3-hgv3-pg44: Various memory and file descriptor leaks were found in apt-python files python/arfile
ghsa_unreviewed·2022-05-24
CVE-2020-27351 [LOW] CWE-772 GHSA-mfw3-hgv3-pg44: Various memory and file descriptor leaks were found in apt-python files python/arfile
Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;
OSV
CVE-2020-27351: Various memory and file descriptor leaks were found in apt-python files python/arfile
osv·2020-12-10·CVSS 2.8
CVE-2020-27351 [LOW] CVE-2020-27351: Various memory and file descriptor leaks were found in apt-python files python/arfile
Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-10
Published