← Vulnerability feed

Vulnerability record · CVE-2020-27350 · published 10 December 2020

CVE-2020-27350: Debian advanced package tool integer overflow vulnerability

Debian · Advanced Package Tool

APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;

5.7 CVSS 3.1 Medium EPSS 0.38% · top 70.5% CWE-190 · Integer overflow
5.7CVSS 3.1 base score, v2 4.6
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. This issue affects: apt 1.2.32ubuntu0 versions prior to 1.2.32ubuntu0.2; 1.6.12ubuntu0 versions prior to 1.6.12ubuntu0.2; 2.0.2ubuntu0 versions prior to 2.0.2ubuntu0.2; 2.1.10ubuntu0 versions prior to 2.1.10ubuntu0.1;

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-27350 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-2215Android Binder use-after-free allows kernel privilege escalationCVE-2019-2215 is a use-after-free in binder.c in the Android/Linux kernel that lets a local application escalate privileges to the kernel. It matters…KEVEPSS 72%analysed10.0CVE-2009-1358Debian advanced package tool vulnerabilityapt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has be…EPSS 4.5%10.0CVE-2009-1300Debian advanced package tool improper input validation vulnerabilityapt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones fo…EPSS 1.9%9.8CVE-2021-33574Gnu glibc use after free vulnerabilityThe mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes ob…EPSS 2.9%9.8CVE-2019-5481Haxx curl double free vulnerabilityDouble-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.EPSS 7.5%9.1CVE-2021-22945Haxx libcurl double free vulnerabilityWhen sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory a…EPSS 6.7%8.8CVE-2021-28660Linux kernel out-of-bounds write vulnerabilityrtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] ar…EPSS 1.3%8.7CVE-2021-22543Linux kernel memory buffer overflow vulnerabilityAn issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed…EPSS 0.66%

Source: NIST National Vulnerability Database (record CVE-2020-27350), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.