CVE-2020-8285
Summary
| CVE | CVE-2020-8285 |
|---|---|
| State | PUBLISHED |
| Assigner | hackerone |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-14 20:15:13 UTC |
| Updated | 2026-04-16 15:16:43 UTC |
| Description | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-674 | CWE-787 | CWE-674 Uncontrolled Recursion (CWE-674)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | ADP | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | All | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Application | Haxx | Libcurl | All | All | All | All |
| Application | Netapp | Clustered Data Ontap | - | All | All | All |
| Operating System | Netapp | Hci Bootstrap Os | - | All | All | All |
| Hardware | Netapp | Hci Compute Node | - | All | All | All |
| Application | Netapp | Hci Management Node | - | All | All | All |
| Hardware | Netapp | Hci Storage Node | - | All | All | All |
| Operating System | Netapp | Hci Storage Node Firmware | - | All | All | All |
| Application | Netapp | Solidfire | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Https//github.com/curl/curl | affected libcurl 7.21.0 to and including 7.73.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| December 2020 cURL/libcURL Vulnerabilities in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| HackerOne | af854a3a-2127-422b-91ae-364da2661108 | hackerone.com | Permissions Required |
| Oracle Critical Patch Update Advisory - July 2021 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| [SECURITY] Fedora 33 Update: curl-7.71.1-8.fc33 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2500-1] curl security update | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| cURL: Multiple vulnerabilities (GLSA 202012-14) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| About the security content of Security Update 2021-002 Catalina - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e69... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Third Party Advisory |
| Oracle Critical Patch Update Advisory - January 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2021 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Patch, Third Party Advisory |
| About the security content of macOS Big Sur 11.3 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| About the security content of Security Update 2021-003 Mojave - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| [SECURITY] Fedora 32 Update: curl-7.69.1-7.fc32 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| Full Disclosure: APPLE-SA-2021-04-26-3 Security Update 2021-002 Catalina | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Mailing List, Third Party Advisory |
| lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450... | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4881-1 curl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| curl - FTP wildcard stack overflow - CVE-2020-8285 | af854a3a-2127-422b-91ae-364da2661108 | curl.se | Vendor Advisory |
| cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | af854a3a-2127-422b-91ae-364da2661108 | cert-portal.siemens.com | Patch, Third Party Advisory |
| Stack overflow in libcurl when CURLOPT_WILDCARDMATCH is in use · Issue #6255 · curl/curl · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Third Party Advisory |
| [SECURITY] Fedora 32 Update: curl-7.69.1-7.fc32 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| [SECURITY] Fedora 33 Update: curl-7.71.1-8.fc33 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 12304 McAfee Web Gateway Product Multiple Vulnerabilities (WP-2326,WP-3443)
- 159196 Oracle Enterprise Linux Security Update for curl (ELSA-2021-1610)
- 178522 Debian Security Update for curl (DSA 4881-1)
- 239328 Red Hat Update for curl (RHSA-2021:1610)
- 239451 Red Hat Update for Red Hat JBoss Core Services Apache HTTP Server 2.4.37 SP8 (RHSA-2021:2472)
- 296067 Oracle Solaris 11.4 Support Repository Update (SRU) 33.94.0 Missing (CPUAPR2021)
- 352506 Amazon Linux Security Advisory for curl: ALAS2-2021-1693
- 375503 Apple MacOS Big Sur 11.3 Not Installed (HT212325)
- 375507 Apple macOS Security Update 2021-002 Catalina (HT212326)
- 375510 Apple macOS Security Update 2021-003 Mojave (HT212327)
- 377396 Alibaba Cloud Linux Security Update for curl (ALINUX3-SA-2021:0078)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 44183 Juniper Network Operating System (Junos OS) Multiple Security Vulnerabilites (JSA79108)
- 500132 Alpine Linux Security Update for curl
- 501396 Alpine Linux Security Update for curl
- 503888 Alpine Linux Security Update for curl
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 670172 EulerOS Security Update for curl (EulerOS-SA-2021-1672)
- 670912 EulerOS Security Update for curl (EulerOS-SA-2021-1287)
- 690348 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (3c77f139-3a09-11eb-929d-d4c9ef517024)
- 750055 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2021:1786-1)
- 750490 OpenSUSE Security Update for curl (openSUSE-SU-2020:2249-1)
- 750492 OpenSUSE Security Update for curl (openSUSE-SU-2020:2238-1)
- 900155 CBL-Mariner Linux Security Update for curl 7.68.0
- 903147 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (3665)
- 940000 AlmaLinux Security Update for curl (ALSA-2021:1610)
- 960740 Rocky Linux Security Update for curl (RLSA-2021:1610)