CVE-2020-27351: Various memory and file descriptor leaks in apt-python
Last updated 25 August 2025
Other sources
Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27351?
CVE-2020-27351 is a vulnerability in python-apt that allows for various memory and file descriptor leaks.
What is the severity of CVE-2020-27351?
CVE-2020-27351 has a severity of low with a severity value of 2.8.
Which software versions are affected by CVE-2020-27351?
CVE-2020-27351 affects python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; and 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2.
How can I fix CVE-2020-27351?
To fix CVE-2020-27351, you should upgrade to python-apt version 1.8.4.3, 2.2.1, or 2.6.0.
Where can I find more information about CVE-2020-27351?
You can find more information about CVE-2020-27351 at the following references: [1] [2] [3].