ISOMAN

CVE

CVE-2020-3810

Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.

Severity
MEDIUM
CVSS
5.5
Published
Modified

Linked Releases

References

  1. https://bugs.launchpad.net/bugs/1878177
  2. https://github.com/Debian/apt/issues/111
  3. https://lists.debian.org/debian-security-announce/2020/msg00089.html
  4. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4PEH357MZM2SUGKETMEHMSGQS652QHH/
  5. https://salsa.debian.org/apt-team/apt/-/commit/dceb1e49e4b8e4dadaf056be34088b415939cda6
  6. https://tracker.debian.org/news/1144109/accepted-apt-212-source-into-unstable/
  7. https://usn.ubuntu.com/4359-1/
  8. https://usn.ubuntu.com/4359-2/
  9. https://bugs.launchpad.net/bugs/1878177
  10. https://github.com/Debian/apt/issues/111
  11. https://lists.debian.org/debian-security-announce/2020/msg00089.html
  12. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4PEH357MZM2SUGKETMEHMSGQS652QHH/
  13. https://salsa.debian.org/apt-team/apt/-/commit/dceb1e49e4b8e4dadaf056be34088b415939cda6
  14. https://tracker.debian.org/news/1144109/accepted-apt-212-source-into-unstable/
  15. https://usn.ubuntu.com/4359-1/
  16. https://usn.ubuntu.com/4359-2/