Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-3810.json"