CVE-2020-3810

NameCVE-2020-3810
DescriptionMissing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2210-1, DSA-4685-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apt (PTS)stretch (security), stretch1.4.10fixed
buster, buster (security)1.8.2.1fixed
bullseye, sid2.1.8fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aptsourcejessie1.0.9.8.6DLA-2210-1
aptsourcestretch1.4.10DSA-4685-1
aptsourcebuster1.8.2.1DSA-4685-1
aptsource(unstable)2.1.2

Notes

https://github.com/Debian/apt/issues/111
https://bugs.launchpad.net/bugs/1878177
https://salsa.debian.org/apt-team/apt/-/commit/dceb1e49e4b8e4dadaf056be34088b415939cda6

Search for package or bug name: Reporting problems