VDB

CVE-2020-27351

CVE-2020-27351 PUBLISHED

Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;

EPSS 0.06% · 19.8th percentile

Risk Scores

EPSS Score
0.06%
19.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSpython-apt*, *, 1.6.5ubuntu0.3
Ubuntu:16.04:LTSpython-apt0, 1.0.1build1, 1.0.1ubuntu2
Ubuntu:20.04:LTSpython-apt2.0.0ubuntu0.20.04.1, 2.0.0, 1.9.10
Ubuntu:Pro:14.04:LTSpython-apt0.9.3.5ubuntu3+esm2, *, 0.9.0

Timeline

  • Dec 9, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›