#VU49491 Integer overflow in apt (Debian package) - CVE-2020-27350
Published: December 10, 2020 / Updated: January 12, 2021
apt (Debian package)
Debian
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to integer overflow while parsing .deb packages in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and apt-pkg/contrib/arfile.cc. A local user can pass specially crafted file to the application, trigger integer overflow and execute arbitrary code on the target system with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.