Description
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2500-1 | curl security update |
Debian DLA |
DLA-3205-1 | inetutils security update |
Debian DSA |
DSA-4881-1 | curl security update |
Ubuntu USN |
USN-4665-1 | curl vulnerabilities |
Ubuntu USN |
USN-4665-2 | curl vulnerabilities |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Apple
Subscribe
Mac Os X
Subscribe
Macos
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Fujitsu
Subscribe
M10-1
Subscribe
M10-1 Firmware
Subscribe
M10-4
Subscribe
M10-4 Firmware
Subscribe
M10-4s
Subscribe
M10-4s Firmware
Subscribe
M12-1
Subscribe
M12-1 Firmware
Subscribe
M12-2
Subscribe
M12-2 Firmware
Subscribe
M12-2s
Subscribe
M12-2s Firmware
Subscribe
Haxx
Subscribe
Curl
Subscribe
Netapp
Subscribe
Clustered Data Ontap
Subscribe
Hci Bootstrap Os
Subscribe
Hci Compute Node
Subscribe
Hci Management Node
Subscribe
Hci Storage Node
Subscribe
Solidfire
Subscribe
Oracle
Subscribe
Communications Billing And Revenue Management
Subscribe
Communications Cloud Native Core Policy
Subscribe
Essbase
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Core Services
Subscribe
Siemens
Subscribe
Sinec Infrastructure Network Services
Subscribe
Splunk
Subscribe
Universal Forwarder
Subscribe
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T09:56:28.316Z
Reserved: 2020-01-28T00:00:00.000Z
Link: CVE-2020-8284
No data.
Status : Modified
Published: 2020-12-14T20:15:13.903
Modified: 2024-11-21T05:38:39.193
Link: CVE-2020-8284
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN