ZeroHour

CVE-2020-8177

PoC
CVSS 3.1
7.8 high
EPSS
1%p68
Published
()
Modified
Description

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

Vendors
haxxdebianfujitsusiemenssplunk
Products
curl, debian linux, m10-1 firmware, m10-4 firmware, m10-4s firmware, m12-1 firmware, m12-2 firmware, m12-2s firmware, sinec infrastructure network services, universal forwarder
Weakness
CWE-99, CWE-74
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.