PT-2020-6226 · Canonical+1 · Apt+2
Kevin Backhouse
·
Published
2020-12-09
·
Updated
2022-10-29
·
CVE-2020-27350
CVSS v3.1
5.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
apt versions 1.2.32ubuntu0 through 1.2.32ubuntu0.1
apt versions 1.6.12ubuntu0 through 1.6.12ubuntu0.1
apt versions 2.0.2ubuntu0 through 2.0.2ubuntu0.1
apt versions 2.1.10ubuntu0 through 2.1.10ubuntu0.0
Description
The issue is related to integer overflows and underflows in the apt package manager while parsing .deb packages. This can be exploited to gain access to confidential data, disrupt data integrity, and cause a denial of service. The affected files are apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc.
Recommendations
For apt version 1.2.32ubuntu0, update to version 1.2.32ubuntu0.2 or later.
For apt version 1.6.12ubuntu0, update to version 1.6.12ubuntu0.2 or later.
For apt version 2.0.2ubuntu0, update to version 2.0.2ubuntu0.2 or later.
For apt version 2.1.10ubuntu0, update to version 2.1.10ubuntu0.1 or later.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Apt