CVE-2020-3810

NameCVE-2020-3810
DescriptionMissing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2210-1, DSA-4685-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apt (PTS)jessie1.0.9.8.4vulnerable
jessie (security)1.0.9.8.6fixed
stretch1.4.9vulnerable
stretch (security)1.4.10fixed
buster1.8.2vulnerable
buster (security)1.8.2.1fixed
bullseye, sid2.1.6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aptsource(unstable)2.1.2
aptsourcebuster1.8.2.1DSA-4685-1
aptsourcejessie1.0.9.8.6DLA-2210-1
aptsourcestretch1.4.10DSA-4685-1

Notes

https://github.com/Debian/apt/issues/111
https://bugs.launchpad.net/bugs/1878177
https://salsa.debian.org/apt-team/apt/-/commit/dceb1e49e4b8e4dadaf056be34088b415939cda6

Search for package or bug name: Reporting problems