Candidate: CVE-2020-27637 PublicDate: 2021-01-12 04:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27637 https://labs.bishopfox.com/advisories/cran-version-4.0.2 https://www.r-project.org/foundation/ Description: The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3 Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_r-base: upstream_r-base: released (4.0.3) precise/esm_r-base: DNE trusty_r-base: ignored (out of standard support) trusty/esm_r-base: needed xenial_r-base: ignored (end of standard support, was needed) bionic_r-base: needed focal_r-base: needed groovy_r-base: ignored (reached end-of-life) hirsute_r-base: not-affected (4.0.3-1) impish_r-base: not-affected (4.0.3-1) jammy_r-base: not-affected (4.0.3-1) devel_r-base: not-affected (4.0.3-1)