CVE-2020-27350
Severity CVSS v4.0:
Pending analysis
Type:
CWE-190
Integer Overflow or Wraparound
Publication date:
10/12/2020
Last modified:
29/10/2022
Description
APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;
Impact
Base Score 3.x
5.70
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:debian:advanced_package_tool:*:*:*:*:*:*:*:* | 1.2.32ubuntu0 (including) | 1.2.32ubuntu0.2 (excluding) |
| cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
| cpe:2.3:a:debian:advanced_package_tool:*:*:*:*:*:*:*:* | 1.6.12ubuntu0 (including) | 1.6.12ubuntu0.2 (excluding) |
| cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
| cpe:2.3:a:debian:advanced_package_tool:*:*:*:*:*:*:*:* | 2.0.2ubuntu0 (including) | 2.0.2ubuntu0.2 (excluding) |
| cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* | ||
| cpe:2.3:a:debian:advanced_package_tool:*:*:*:*:*:*:*:* | 2.1.10ubuntu0 (including) | 2.1.10ubuntu0.2 (excluding) |
| cpe:2.3:o:canonical:ubuntu_linux:20.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:debian:advanced_package_tool:*:*:*:*:*:*:*:* | 1.8.2.2 (excluding) | |
| cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netapp:solidfire_baseboard_management_controller_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



