CVE-2020-3810: Input Validation
Published May 15, 2020
·Updated
Last updated 24 July 2024
Other sources
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
Affected Software
11 affected componentsFixes available
debian/apt
2.2.42.6.12.9.232.9.25
Debian Apt<2.1.2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=32
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
Canonical Ubuntu Linux=20.04
Remediation
Event History
May 15, 2020
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:51 PM
Description
Sep 17, 2024
Data Sourced
via Ubuntu·01:12 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-3810?
CVE-2020-3810 has been classified as a medium severity vulnerability due to its potential for denial of service.
2
How do I fix CVE-2020-3810?
To fix CVE-2020-3810, upgrade APT to version 2.1.2 or later.
3
Which software is affected by CVE-2020-3810?
CVE-2020-3810 affects APT versions prior to 2.1.2 across multiple Debian and Ubuntu distributions.
4
What type of vulnerability is CVE-2020-3810?
CVE-2020-3810 is a missing input validation vulnerability leading to potential denial of service.
5
Can CVE-2020-3810 be exploited remotely?
Yes, CVE-2020-3810 can be exploited remotely when processing specially crafted deb files.