CVE-2020-8285

HIGHCVSS 7.5/10EPSS 9.92%

Last modified

CVE-2020-8285 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.. EPSS estimates a 9.92% chance of exploitation in the next 30 days.

Description

curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
9.92%

95.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HaxxLibcurl>= 7.21.0, < 7.74.0
DebianDebian Linux9.0
DebianDebian Linux10.0
FedoraprojectFedora32
FedoraprojectFedora33
NetappClustered Data OntapAll versions
NetappHci Management NodeAll versions
NetappSolidfireAll versions
NetappHci Bootstrap OsAll versions
NetappHci Storage Node FirmwareAll versions
AppleMac Os X< 10.14.6
AppleMac Os X>= 10.15, < 10.15.7
AppleMac Os X10.14.6
AppleMac Os X10.15.7
AppleMacos>= 11.0, < 11.3
OracleCommunications Billing And Revenue Management12.0.0.3.0
OracleCommunications Cloud Native Core Policy1.14.0
OracleEssbase21.2
OraclePeoplesoft Enterprise Peopletools8.58
FujitsuM10-1 Firmware< xcp2410
FujitsuM10-4 Firmware< xcp2410
FujitsuM10-4s Firmware< xcp2410
FujitsuM12-1 Firmware< xcp2410
FujitsuM12-2 Firmware< xcp2410
FujitsuM12-2s Firmware< xcp2410
FujitsuM10-1 Firmware< xcp3110
FujitsuM10-4 Firmware< xcp3110
FujitsuM10-4s Firmware< xcp3110
FujitsuM12-1 Firmware< xcp3110
FujitsuM12-2 Firmware< xcp3110
FujitsuM12-2s Firmware< xcp3110
SiemensSinec Infrastructure Network Services< 1.0.1.1
SplunkUniversal Forwarder>= 8.2.0, < 8.2.12
SplunkUniversal Forwarder>= 9.0.0, < 9.0.6
SplunkUniversal Forwarder9.1.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-8285?
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
How severe is CVE-2020-8285?
CVE-2020-8285 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 9.92% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8285?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8285?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST