CVE-2020-8285
published 2020-12-14CVE-2020-8285: curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
9.92%
95.1th percentile
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.14.6 | 10.14.6 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.3 | 11.3 |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-002_catalina | — | — |
| debian | curl | < curl 7.74.0-1 (bookworm) | curl 7.74.0-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fujitsu | m10-1_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-1_firmware | < xcp3110 | xcp3110 |
| fujitsu | m10-4_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-4_firmware | < xcp3110 | xcp3110 |
| fujitsu | m10-4s_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-4s_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-1_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-1_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-2_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-2_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-2s_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-2s_firmware | < xcp3110 | xcp3110 |
| haxx | curl | >= 0 < 7.74.0-1 | 7.74.0-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Oracle
Oracle Oracle Systems Risk Matrix: XCP Firmware (cURL) — CVE-2020-8285
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2020-8285 [HIGH] Oracle Oracle Systems Risk Matrix: XCP Firmware (cURL) — CVE-2020-8285
Oracle Oracle Systems Risk Matrix: XCP Firmware (cURL) vulnerability
CVE: CVE-2020-8285
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Essbase Risk Matrix: Infrastructure (cURL) — CVE-2020-8285
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2020-8285 [HIGH] Oracle Oracle Essbase Risk Matrix: Infrastructure (cURL) — CVE-2020-8285
Oracle Oracle Essbase Risk Matrix: Infrastructure (cURL) vulnerability
CVE: CVE-2020-8285
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Apple
CVE-2020-8285: Security Update 2021-002 Catalina
vendor_apple·2021-04-26·CVSS 7.5
CVE-2020-8285 [HIGH] CVE-2020-8285: Security Update 2021-002 Catalina
Apple Security Update: About the security content of Security Update 2021-002 Catalina
Product: Security Update 2021-002 Catalina
CVE: CVE-2020-8285
Component: CoreText
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: A logic issue was addressed with improved state management.
Apple
CVE-2020-8285: macOS Big Sur 11.3
vendor_apple·2021-04-26·CVSS 7.5
CVE-2020-8285 [HIGH] CVE-2020-8285: macOS Big Sur 11.3
Apple Security Update: About the security content of macOS Big Sur 11.3
Product: macOS Big Sur
Version: 11.3
CVE: CVE-2020-8285
Component: CoreText
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: A logic issue was addressed with improved state management.
Red Hat
curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used
vendor_redhat·2020-12-09·CVSS 7.5
CVE-2020-8285 [HIGH] CWE-674 curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used
curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
Libcurl offers a wildcard matching functionality, which allows a callback (set with `CURLOPT_CHUNK_BGN_FUNCTION`) to return information back to libcurl on how to handle a specific entry in a directory when libcurl iterates over a list of all available entries. When this callback returns `CURL_CHUNK_BGN_FUNC_SKIP`, to tell libcurl to not deal with that file, the internal function in libcurl then calls itself recursively to handle the next directory entry. If there's a sufficient amount of file entries and if the callback returns "skip" enough number of times, li
Ubuntu
curl vulnerabilities
vendor_ubuntu·2020-12-09·CVSS 3.7
CVE-2020-8285 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
USN-4665-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Varnavas Papaioannou discovered that curl incorrectly handled FTP PASV
responses. An attacker could possibly use this issue to trick curl into
connecting to an arbitrary IP address and be used to perform port scanner
and other information gathering. (CVE-2020-8284)
It was discovered that curl incorrectly handled FTP wildcard matchins. A
remote attacker could possibly use this issue to cause curl to consume
resources and crash, resulting in a denial of service. (CVE-2020-8285)
Instructions: In general, a standard system update will make all t
Ubuntu
curl vulnerabilities
vendor_ubuntu·2020-12-09·CVSS 7.5
CVE-2020-8286 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Marc Aldorasi discovered that curl incorrectly handled the libcurl
CURLOPT_CONNECT_ONLY option. This could result in data being sent to the
wrong destination, possibly exposing sensitive information. This issue only
affected Ubuntu 20.10. (CVE-2020-8231)
Varnavas Papaioannou discovered that curl incorrectly handled FTP PASV
responses. An attacker could possibly use this issue to trick curl into
connecting to an arbitrary IP address and be used to perform port scanner
and other information gathering. (CVE-2020-8284)
It was discovered that curl incorrectly handled FTP wildcard matchins. A
remote attacker could possibly use this issue to cause curl to consume
resources and crash, resulting in a denial of serv
Microsoft
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
vendor_msrc·2020-12-08·CVSS 7.5
CVE-2020-8285 [HIGH] CWE-787 curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
hackerone: hackerone
C
Debian
CVE-2020-8285: curl - curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due ...
vendor_debian·2020·CVSS 7.5
CVE-2020-8285 [HIGH] CVE-2020-8285: curl - curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due ...
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
Scope: local
bookworm: resolved (fixed in 7.74.0-1)
bullseye: resolved (fixed in 7.74.0-1)
forky: resolved (fixed in 7.74.0-1)
sid: resolved (fixed in 7.74.0-1)
trixie: resolved (fixed in 7.74.0-1)
GHSA
GHSA-4p2h-jggv-23jg: curl 7
ghsa_unreviewed·2022-05-24
CVE-2020-8285 [HIGH] CWE-674 GHSA-4p2h-jggv-23jg: curl 7
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
OSV
CVE-2020-8285: curl 7
osv·2020-12-14·CVSS 7.5
CVE-2020-8285 [HIGH] CVE-2020-8285: curl 7
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
OSV
curl vulnerabilities
osv·2020-12-09·CVSS 7.5
CVE-2020-8231 [HIGH] curl vulnerabilities
curl vulnerabilities
Marc Aldorasi discovered that curl incorrectly handled the libcurl
CURLOPT_CONNECT_ONLY option. This could result in data being sent to the
wrong destination, possibly exposing sensitive information. This issue only
affected Ubuntu 20.10. (CVE-2020-8231)
Varnavas Papaioannou discovered that curl incorrectly handled FTP PASV
responses. An attacker could possibly use this issue to trick curl into
connecting to an arbitrary IP address and be used to perform port scanner
and other information gathering. (CVE-2020-8284)
It was discovered that curl incorrectly handled FTP wildcard matchins. A
remote attacker could possibly use this issue to cause curl to consume
resources and crash, resulting in a denial of service. (CVE-2020-8285)
It was discovered that curl incorrectly
OSV
curl vulnerabilities
osv·2020-12-09·CVSS 3.7
CVE-2020-8284 [LOW] curl vulnerabilities
curl vulnerabilities
USN-4665-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Varnavas Papaioannou discovered that curl incorrectly handled FTP PASV
responses. An attacker could possibly use this issue to trick curl into
connecting to an arbitrary IP address and be used to perform port scanner
and other information gathering. (CVE-2020-8284)
It was discovered that curl incorrectly handled FTP wildcard matchins. A
remote attacker could possibly use this issue to cause curl to consume
resources and crash, resulting in a denial of service. (CVE-2020-8285)
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2021/Apr/51https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://curl.se/docs/CVE-2020-8285.htmlhttps://github.com/curl/curl/issues/6255https://hackerone.com/reports/1045844https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/12/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/https://security.gentoo.org/glsa/202012-14https://security.netapp.com/advisory/ntap-20210122-0007/https://support.apple.com/kb/HT212325https://support.apple.com/kb/HT212326https://support.apple.com/kb/HT212327https://www.debian.org/security/2021/dsa-4881https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttp://seclists.org/fulldisclosure/2021/Apr/51https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://curl.se/docs/CVE-2020-8285.htmlhttps://github.com/curl/curl/issues/6255https://hackerone.com/reports/1045844https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/12/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/https://security.gentoo.org/glsa/202012-14https://security.netapp.com/advisory/ntap-20210122-0007/https://support.apple.com/kb/HT212325https://support.apple.com/kb/HT212326https://support.apple.com/kb/HT212327https://www.debian.org/security/2021/dsa-4881https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2020-12-14
Published