CVE-2020-8285

HIGH

libcurl 7.21.0-7.73.0 - Uncontrolled Recursion via FTP Wildcard Match Parsing

Title source: llm
STIX 2.1

Description

curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.

References (20)

Core 20
Core References
Permissions Required x_refsource_misc
https://hackerone.com/reports/1045844
Exploit, Third Party Advisory x_refsource_misc
https://github.com/curl/curl/issues/6255
Vendor Advisory x_refsource_misc
https://curl.se/docs/CVE-2020-8285.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202012-14
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4881
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2021/Apr/51
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210122-0007/
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212325
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212326
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT212327
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch, Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf

Scores

CVSS v3 7.5
EPSS 0.0074
EPSS Percentile 73.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-674 CWE-787
Status published
Products (28)
None/https://github.com/curl/curl libcurl 7.21.0 to and including 7.73.0
apple/mac_os_x 10.14.6 (11 CPE variants)
apple/mac_os_x 10.15.7 (4 CPE variants)
apple/mac_os_x < 10.14.6
apple/macos 11.0 - 11.3
debian/debian_linux 9.0
debian/debian_linux 10.0
fedoraproject/fedora 32
fedoraproject/fedora 33
fujitsu/m10-1_firmware < xcp2410
... and 18 more
Published Dec 14, 2020
Tracked Since Feb 18, 2026