CVE-2020-27350: Debian Advanced Package Tool

Medium severity, CVSS 5.7. EPSS: 0.4% chance of exploitation in the next 30 days.

APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;

Affected products

  • Debian Advanced Package Tool: from 1.2.32ubuntu0, before 1.2.32ubuntu0.2 (fixed in 1.2.32ubuntu0.2); from 1.6.12ubuntu0, before 1.6.12ubuntu0.2 (fixed in 1.6.12ubuntu0.2); from 2.0.2ubuntu0, before 2.0.2ubuntu0.2 (fixed in 2.0.2ubuntu0.2); from 2.1.10ubuntu0, before 2.1.10ubuntu0.2 (fixed in 2.1.10ubuntu0.2); before 1.8.2.2 (fixed in 1.8.2.2)
  • Netapp Solidfire Baseboard Management Controller Firmware: affected versions not specified

Published 2020-12-10. Last modified 2026-06-17.