cbcvebase.
CVE-2020-8284
published 2020-12-14

CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially…

low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x
applemac_os_x>= 10.14.0 < 10.14.610.14.6
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos
applemacos
applemacos
applemacos_big_sur
applesecurity_update_2021-002_catalina
debiancurl< curl 7.74.0-1 (bookworm)curl 7.74.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
debianinetutils< inetutils 2:2.2-1 (bookworm)inetutils 2:2.2-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fujitsum10-1_firmware< xcp2410xcp2410
fujitsum10-1_firmware< xcp3110xcp3110
fujitsum10-4_firmware< xcp2410xcp2410
fujitsum10-4_firmware< xcp3110xcp3110
fujitsum10-4s_firmware< xcp2410xcp2410
fujitsum10-4s_firmware< xcp3110xcp3110
fujitsum12-1_firmware< xcp2410xcp2410
fujitsum12-1_firmware< xcp3110xcp3110
fujitsum12-2_firmware< xcp2410xcp2410
fujitsum12-2_firmware< xcp3110xcp3110

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv7.5HIGH