|
1427 | 1427 | } |
1428 | 1428 | ] |
1429 | 1429 | }, |
| 1430 | + { |
| 1431 | + "id": "CVE-2020-8285", |
| 1432 | + "details": "curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.", |
| 1433 | + "aliases": ["CURL-CVE-2020-8285"], |
| 1434 | + "modified": "<RFC3339 date with the year 2026>", |
| 1435 | + "published": "2020-12-14T20:15:13.983Z", |
| 1436 | + "related": [ |
| 1437 | + "MGASA-2020-0482", |
| 1438 | + "SUSE-SU-2020:14585-1", |
| 1439 | + "SUSE-SU-2020:3733-1", |
| 1440 | + "SUSE-SU-2020:3735-1", |
| 1441 | + "SUSE-SU-2020:3739-1", |
| 1442 | + "SUSE-SU-2021:1786-1", |
| 1443 | + "openSUSE-SU-2020:2238-1", |
| 1444 | + "openSUSE-SU-2020:2249-1", |
| 1445 | + "openSUSE-SU-2024:10582-1" |
| 1446 | + ], |
| 1447 | + "references": [ |
| 1448 | + { |
| 1449 | + "type": "ADVISORY", |
| 1450 | + "url": "http://seclists.org/fulldisclosure/2021/Apr/51" |
| 1451 | + }, |
| 1452 | + { |
| 1453 | + "type": "ADVISORY", |
| 1454 | + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf" |
| 1455 | + }, |
| 1456 | + { |
| 1457 | + "type": "ADVISORY", |
| 1458 | + "url": "https://curl.se/docs/CVE-2020-8285.html" |
| 1459 | + }, |
| 1460 | + { |
| 1461 | + "type": "ADVISORY", |
| 1462 | + "url": "https://github.com/curl/curl/issues/6255" |
| 1463 | + }, |
| 1464 | + { |
| 1465 | + "type": "ADVISORY", |
| 1466 | + "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E" |
| 1467 | + }, |
| 1468 | + { |
| 1469 | + "type": "ADVISORY", |
| 1470 | + "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E" |
| 1471 | + }, |
| 1472 | + { |
| 1473 | + "type": "ADVISORY", |
| 1474 | + "url": "https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html" |
| 1475 | + }, |
| 1476 | + { |
| 1477 | + "type": "ADVISORY", |
| 1478 | + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/" |
| 1479 | + }, |
| 1480 | + { |
| 1481 | + "type": "ADVISORY", |
| 1482 | + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/" |
| 1483 | + }, |
| 1484 | + { |
| 1485 | + "type": "ADVISORY", |
| 1486 | + "url": "https://security.gentoo.org/glsa/202012-14" |
| 1487 | + }, |
| 1488 | + { |
| 1489 | + "type": "ADVISORY", |
| 1490 | + "url": "https://security.netapp.com/advisory/ntap-20210122-0007/" |
| 1491 | + }, |
| 1492 | + { |
| 1493 | + "type": "ADVISORY", |
| 1494 | + "url": "https://support.apple.com/kb/HT212325" |
| 1495 | + }, |
| 1496 | + { |
| 1497 | + "type": "ADVISORY", |
| 1498 | + "url": "https://support.apple.com/kb/HT212326" |
| 1499 | + }, |
| 1500 | + { |
| 1501 | + "type": "ADVISORY", |
| 1502 | + "url": "https://support.apple.com/kb/HT212327" |
| 1503 | + }, |
| 1504 | + { |
| 1505 | + "type": "ADVISORY", |
| 1506 | + "url": "https://www.debian.org/security/2021/dsa-4881" |
| 1507 | + }, |
| 1508 | + { |
| 1509 | + "type": "ADVISORY", |
| 1510 | + "url": "https://www.oracle.com//security-alerts/cpujul2021.html" |
| 1511 | + }, |
| 1512 | + { |
| 1513 | + "type": "ADVISORY", |
| 1514 | + "url": "https://www.oracle.com/security-alerts/cpuApr2021.html" |
| 1515 | + }, |
| 1516 | + { |
| 1517 | + "type": "ADVISORY", |
| 1518 | + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" |
| 1519 | + }, |
| 1520 | + { |
| 1521 | + "type": "ADVISORY", |
| 1522 | + "url": "https://www.oracle.com/security-alerts/cpujan2022.html" |
| 1523 | + }, |
| 1524 | + { |
| 1525 | + "type": "REPORT", |
| 1526 | + "url": "https://hackerone.com/reports/1045844" |
| 1527 | + }, |
| 1528 | + { |
| 1529 | + "type": "FIX", |
| 1530 | + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf" |
| 1531 | + }, |
| 1532 | + { |
| 1533 | + "type": "FIX", |
| 1534 | + "url": "https://www.oracle.com//security-alerts/cpujul2021.html" |
| 1535 | + }, |
| 1536 | + { |
| 1537 | + "type": "FIX", |
| 1538 | + "url": "https://www.oracle.com/security-alerts/cpuApr2021.html" |
| 1539 | + }, |
| 1540 | + { |
| 1541 | + "type": "FIX", |
| 1542 | + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" |
| 1543 | + }, |
| 1544 | + { |
| 1545 | + "type": "FIX", |
| 1546 | + "url": "https://www.oracle.com/security-alerts/cpujan2022.html" |
| 1547 | + }, |
| 1548 | + { |
| 1549 | + "type": "ARTICLE", |
| 1550 | + "url": "http://seclists.org/fulldisclosure/2021/Apr/51" |
| 1551 | + }, |
| 1552 | + { |
| 1553 | + "type": "ARTICLE", |
| 1554 | + "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E" |
| 1555 | + }, |
| 1556 | + { |
| 1557 | + "type": "ARTICLE", |
| 1558 | + "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E" |
| 1559 | + }, |
| 1560 | + { |
| 1561 | + "type": "ARTICLE", |
| 1562 | + "url": "https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html" |
| 1563 | + }, |
| 1564 | + { |
| 1565 | + "type": "ARTICLE", |
| 1566 | + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/" |
| 1567 | + }, |
| 1568 | + { |
| 1569 | + "type": "ARTICLE", |
| 1570 | + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/" |
| 1571 | + }, |
| 1572 | + { |
| 1573 | + "type": "EVIDENCE", |
| 1574 | + "url": "https://github.com/curl/curl/issues/6255" |
| 1575 | + } |
| 1576 | + ], |
| 1577 | + "affected": [ |
| 1578 | + { |
| 1579 | + "ranges": [ |
| 1580 | + { |
| 1581 | + "type": "GIT", |
| 1582 | + "repo": "https://github.com/curl/curl", |
| 1583 | + "events": [ |
| 1584 | + { |
| 1585 | + "introduced": "e91d167ff8cb89523447680e3560f60d93615055" |
| 1586 | + }, |
| 1587 | + { |
| 1588 | + "fixed": "80acd2b02e3caf9d6f9e3dd2ce6813b109a468a9" |
| 1589 | + } |
| 1590 | + ] |
| 1591 | + } |
| 1592 | + ], |
| 1593 | + "versions": 132, |
| 1594 | + "database_specific": "<Any value>" |
| 1595 | + } |
| 1596 | + ], |
| 1597 | + "schema_version": "1.7.3", |
| 1598 | + "severity": [ |
| 1599 | + { |
| 1600 | + "type": "CVSS_V3", |
| 1601 | + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" |
| 1602 | + } |
| 1603 | + ] |
| 1604 | + }, |
1430 | 1605 | { |
1431 | 1606 | "id": "CVE-2024-0853", |
1432 | 1607 | "details": "curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to\nthe same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.", |
|
0 commit comments