cbcvebase.
CVE-2020-8285
published 2020-12-14

CVE-2020-8285: curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x< 10.14.610.14.6
applemac_os_x
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.311.3
applemacos_big_sur
applesecurity_update_2021-002_catalina
debiancurl< curl 7.74.0-1 (bookworm)curl 7.74.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fujitsum10-1_firmware< xcp2410xcp2410
fujitsum10-1_firmware< xcp3110xcp3110
fujitsum10-4_firmware< xcp2410xcp2410
fujitsum10-4_firmware< xcp3110xcp3110
fujitsum10-4s_firmware< xcp2410xcp2410
fujitsum10-4s_firmware< xcp3110xcp3110
fujitsum12-1_firmware< xcp2410xcp2410
fujitsum12-1_firmware< xcp3110xcp3110
fujitsum12-2_firmware< xcp2410xcp2410
fujitsum12-2_firmware< xcp3110xcp3110
fujitsum12-2s_firmware< xcp2410xcp2410
fujitsum12-2s_firmware< xcp3110xcp3110
haxxcurl>= 0 < 7.74.0-17.74.0-1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH