ZeroHour

CVE-2020-8285

PoC
CVSS 3.1
7.5 high
EPSS
10%p95
Published
()
Modified
Description

curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.

Vendors
haxxdebianfedoraprojectnetappappleoraclefujitsusiemenssplunk
Products
libcurl, debian linux, fedora, clustered data ontap, hci management node, solidfire, hci bootstrap os, hci storage node firmware, mac os x, macos, communications billing and revenue management, communications cloud native core policy
Weakness
CWE-674, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.