CVE-2020-15690
Summary
| CVE | CVE-2020-15690 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-30 06:15:00 UTC |
| Updated | 2021-02-09 18:50:00 UTC |
| Description | In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nim - stdlib asyncftpd - Crlf Injection | ConsenSys Diligence | MISC | consensys.net | Exploit, Third Party Advisory |
| oss-security - [CVE-2020-15690] Nim - stdlib asyncftpd - Crlf Injection | MLIST | www.openwall.com | Exploit, Mailing List, Third Party Advisory |
| pub/pocs/cve-2020-15690 at master · tintinweb/pub · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| Comparing v1.2.4...v1.2.6 · nim-lang/Nim · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Nim/asyncftpclient.nim at dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99 · nim-lang/Nim · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180725 Debian Security Update for nim (CVE-2020-15690)