Do your applications use this vulnerable package?
Test your applications
Overview
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
References
CVSS Score
5.5
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2020-3810
- CWE
- CWE-20
- Snyk ID
- SNYK-DEBIAN9-APT-568929
- Disclosed
- 15 May, 2020
- Published
- 12 May, 2020