CVE-2020-27351: Debian Advanced Package Tool
Low severity, CVSS 2.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;
Affected products
- Debian Advanced Package Tool: from 1.1.0\~beta1, before 1.1.0\~beta1ubuntu0.16.04.10 (fixed in 1.1.0\~beta1ubuntu0.16.04.10); from 1.6.5ubuntu0, before 1.6.5ubuntu0.4 (fixed in 1.6.5ubuntu0.4); from 2.0.0ubuntu0, before 2.0.0ubuntu0.20.04.2 (fixed in 2.0.0ubuntu0.20.04.2); from 2.1.3ubuntu1, before 2.1.30ubuntu1.1 (fixed in 2.1.30ubuntu1.1); before 1.8.4.2 (fixed in 1.8.4.2)
Published 2020-12-10. Last modified 2026-06-17.