Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://github.com/Debian/apt/issues/111 | third party advisory exploit |
https://bugs.launchpad.net/bugs/1878177 | issue tracking third party advisory |
https://salsa.debian.org/apt-team/apt/-/commit/dceb1e49e4b8e4dadaf056be34088b415939cda6 | patch vendor advisory |
https://lists.debian.org/debian-security-announce/2020/msg00089.html | mailing list vendor advisory |
https://tracker.debian.org/news/1144109/accepted-apt-212-source-into-unstable/ | release notes vendor advisory |
https://usn.ubuntu.com/4359-1/ | third party advisory vendor advisory |
https://usn.ubuntu.com/4359-2/ | third party advisory vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U4PEH357MZM2SUGKETMEHMSGQS652QHH/ | vendor advisory |