CVE-2020-8285
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
Affected (48)
Show all products
Haxx: Libcurl · Debian: Debian Linux · Fedoraproject: Fedora · Netapp: Clustered Data Ontap, Hci Management Node, Solidfire, Hci Bootstrap Os, Hci Storage Node Firmware · Apple: Mac Os X, Macos · Oracle: Communications Billing And Revenue Management, Communications Cloud Native Core Policy, Essbase, Peoplesoft Enterprise Peopletools · Fujitsu: M10 1 Firmware, M10 4 Firmware, M10 4s Firmware, M12 1 Firmware, M12 2 Firmware, M12 2s Firmware · Siemens: Sinec Infrastructure Network Services · Splunk: Universal Forwarder
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 32 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Hci Compute Node | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Hci Storage Node | All versions |
Configuration G
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.0.0.3.0 | |
| Version 1.14.0 | |
| Version 21.2 | |
| Version 8.58 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 1 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4s | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 1 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2s | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.1 |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.2.0 to 8.2.12 |
Related CWEs
References (40)
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Mailing ListThird Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.