Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-8284

Опубликовано: 14 дек. 2020
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 3.7

Описание

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

РелизСтатусПримечание
bionic

released

7.58.0-2ubuntu3.12
devel

released

7.74.0-1ubuntu1
esm-infra-legacy/trusty

released

7.35.0-1ubuntu2.20+esm6
esm-infra-legacy/xenial

released

7.47.0-1ubuntu2.18
esm-infra/bionic

released

7.58.0-2ubuntu3.12
esm-infra/focal

released

7.68.0-1ubuntu2.4
esm-infra/xenial

released

7.47.0-1ubuntu2.18
focal

released

7.68.0-1ubuntu2.4
groovy

released

7.68.0-1ubuntu4.2
precise/esm

not-affected

7.22.0-3ubuntu4.29

Показывать по

EPSS

Процентиль: 89%
0.03851
Низкий

4.3 Medium

CVSS2

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
redhat
больше 5 лет назад

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

CVSS3: 3.7
nvd
больше 5 лет назад

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

CVSS3: 3.7
msrc
больше 5 лет назад

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port and this way potentially make curl extract information about services that are otherwise private and not disclosed for example doing port scanning and service banner extractions.

CVSS3: 3.7
debian
больше 5 лет назад

A malicious server can use the FTP PASV response to trick curl 7.73.0 ...

CVSS3: 3.7
github
около 4 лет назад

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

EPSS

Процентиль: 89%
0.03851
Низкий

4.3 Medium

CVSS2

3.7 Low

CVSS3