CVE-2020-3810
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
Affected (10)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1.2 | |
| Version 10.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 32 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.04 |
Related CWEs
CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
References (16)
Source: security@debian.org
Issue TrackingThird Party Advisory
Source: security@debian.org
Mailing ListVendor Advisory
Source: security@debian.org
Source: security@debian.org
PatchVendor Advisory
Source: security@debian.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Timeline
No history available yet.