Integer Overflow or Wraparound
Affecting apt package, versions <1.6.12ubuntu0.2
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Integer Overflow or Wraparound. APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;
Remediation
Upgrade apt
to version or higher.
References
CVSS Score
5.7
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredHigh
-
User InteractionNone
-
ScopeChanged
-
ConfidentialityLow
-
IntegrityLow
-
AvailabilityLow
- CVE
- CVE-2020-27350
- CWE
- CWE-190
- Snyk ID
- SNYK-UBUNTU1804-APT-1050039
- Disclosed
- 10 Dec, 2020
- Published
- 10 Dec, 2020