It was discovered that the getmodifiedconffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32556.json"
[
{
"events": [
{
"introduced": "2.14.1-0ubuntu3"
},
{
"fixed": "2.14.1-0ubuntu3.29\\+esm7"
}
]
},
{
"events": [
{
"introduced": "2.20.1"
},
{
"fixed": "2.20.1-0ubuntu2.30\\+esm1"
}
]
},
{
"events": [
{
"introduced": "2.20.9"
},
{
"fixed": "2.20.9-0ubuntu7.24"
}
]
},
{
"events": [
{
"introduced": "2.20.11-0ubuntu27"
},
{
"fixed": "2.20.11-0ubuntu27.18"
}
]
},
{
"events": [
{
"introduced": "2.20.11-0ubuntu50"
},
{
"fixed": "2.20.11-0ubuntu50.7"
}
]
},
{
"events": [
{
"introduced": "2.20.11-0ubuntu65"
},
{
"fixed": "2.20.11-0ubuntu65.1"
}
]
}
]