CVE-2020-27351

NameCVE-2020-27351
DescriptionVarious memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2488-1, DSA-4809-1, ELA-359-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-apt (PTS)jessie, jessie (lts)0.9.3.14fixed
stretch (security), stretch (lts), stretch1.4.3fixed
buster, buster (security)1.8.4.3fixed
bullseye2.2.1fixed
sid, bookworm2.5.2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-aptsourcejessie0.9.3.14ELA-359-1
python-aptsourcestretch1.4.2DLA-2488-1
python-aptsourcebuster1.8.4.2DSA-4809-1
python-aptsource(unstable)2.1.7

Notes

https://bugs.launchpad.net/bugs/1899193

Search for package or bug name: Reporting problems