curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used
Published Dec 14, 2020
7.5
HIGHCVSS 3.1
EPSS 9.77%
Description
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
Affected products
No data.
Configuration 2
- 9.0
- 10.0
Configuration 3
- 32
- 33
Configuration 4
- n/a
- n/a
- n/a
Configuration 5
- n/a
Running on/with
- n/a
Configuration 6
- n/a
Running on/with
- n/a
Configuration 7
- < 10.14.6
- ≥ 10.15 · < 10.15.7
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.14.6
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- ≥ 11.0 · < 11.3
Configuration 8
- 12.0.0.3.0
- 1.14.0
- 21.2
- 8.58
Configuration 9
- < xcp2410
Configuration 10
- < xcp2410
Configuration 11
- < xcp2410
Configuration 12
- < xcp2410
Configuration 13
- < xcp2410
Configuration 14
- < xcp2410
Configuration 15
- < xcp3110
Configuration 16
- < xcp3110
Configuration 17
- < xcp3110
Configuration 18
- < xcp3110
Configuration 19
- < xcp3110
Configuration 20
- < xcp3110
Configuration 21
- < 1.0.1.1
Configuration 22
- ≥ 8.2.0 · < 8.2.12
- ≥ 9.0.0 · < 9.0.6
- 9.1.0
No data.
JBoss Core Services Apache HTTP Server 2.4.37 SP8
jbcs-httpd24-curl
Fixed · RHSA-2021:2471
JBoss Core Services for RHEL 8
jbcs-httpd24-0:1-18.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-apr-0:1.6.3-105.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-apr-util-0:1.6.1-82.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-brotli-0:1.0.6-40.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-curl-0:7.77.0-2.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-httpd-0:2.4.37-74.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-jansson-0:2.11-55.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_http2-0:1.15.7-17.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_md-1:2.0.8-36.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_security-0:2.9.2-63.GA.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-nghttp2-0:1.39.2-37.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-1:1.1.1g-6.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-chil-0:1.0.0-5.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-pkcs11-0:0.4.10-20.el8jbcs
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-0:1-18.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-0:1.6.3-105.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-util-0:1.6.1-82.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-curl-0:7.77.0-2.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-74.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-jansson-0:2.11-55.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_http2-0:1.15.7-17.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_md-1:2.0.8-36.jbcs.el7
Fixed · RHSA-2021:2472
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.2-63.GA.jbcs.el7
Fixed · RHSA-2021:2472
Red Hat Enterprise Linux 8
curl-0:7.61.1-18.el8
Fixed · RHSA-2021:1610
.NET Core 2.1 on Red Hat Enterprise Linux
rh-dotnet21-curl
Not affected
.NET Core 3.1 on Red Hat Enterprise Linux
rh-dotnet31-curl
Not affected
Red Hat Ceph Storage 2
curl
Out of support scope
Red Hat Enterprise Linux 5
curl
Out of support scope
Red Hat Enterprise Linux 6
curl
Out of support scope
Red Hat Enterprise Linux 7
curl
Out of support scope
Red Hat Software Collections
httpd24-curl
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services Apache HTTP Server 2.4.37 SP8 | jbcs-httpd24-curl | Fixed | RHSA-2021:2471 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-0:1-18.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-apr-0:1.6.3-105.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-apr-util-0:1.6.1-82.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-brotli-0:1.0.6-40.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-curl-0:7.77.0-2.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd-0:2.4.37-74.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-jansson-0:2.11-55.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_http2-0:1.15.7-17.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_md-1:2.0.8-36.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_security-0:2.9.2-63.GA.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-nghttp2-0:1.39.2-37.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-1:1.1.1g-6.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-chil-0:1.0.0-5.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-pkcs11-0:0.4.10-20.el8jbcs | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-0:1-18.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-0:1.6.3-105.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-util-0:1.6.1-82.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-curl-0:7.77.0-2.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-74.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-jansson-0:2.11-55.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.16-5.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2-0:1.15.7-17.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.48-16.redhat_1.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_md-1:2.0.8-36.jbcs.el7 | Fixed | RHSA-2021:2472 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.2-63.GA.jbcs.el7 | Fixed | RHSA-2021:2472 |
| Red Hat Enterprise Linux 8 | curl-0:7.61.1-18.el8 | Fixed | RHSA-2021:1610 |
| .NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21-curl | Not affected | n/a |
| .NET Core 3.1 on Red Hat Enterprise Linux | rh-dotnet31-curl | Not affected | n/a |
| Red Hat Ceph Storage 2 | curl | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | curl | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | curl | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | curl | Out of support scope | n/a |
| Red Hat Software Collections | httpd24-curl | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 16, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (28 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 9.77% (0.09770) | 95.40th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.92% (0.09917) | 94.96th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.59% (0.00594) | 68.45th | v4 (v2025.03.14) |
| Nov 18, 2025 | 11.66% (0.11660) | 92.97th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.21% (0.00205) | 40.66th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.61% (0.00611) | 79.35th | v3 (v2023.03.01) |
| Apr 21, 2024 | 0.71% (0.00710) | 80.23th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.79% (0.00792) | 79.52th | v3 (v2023.03.01) |
| Oct 23, 2023 | 0.71% (0.00710) | 78.24th | v3 (v2023.03.01) |
| Aug 30, 2023 | 0.50% (0.00501) | 73.38th | v3 (v2023.03.01) |
| Jul 21, 2023 | 0.46% (0.00461) | 72.07th | v3 (v2023.03.01) |
| Jul 9, 2023 | 0.38% (0.00381) | 69.26th | v3 (v2023.03.01) |
| Jun 12, 2023 | 0.51% (0.00511) | 73.27th | v3 (v2023.03.01) |
| May 16, 2023 | 0.45% (0.00450) | 71.38th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.36% (0.00364) | 68.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 23.44% (0.23437) | 94.77th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.44% (0.02444) | 53.99th | v1 |
| Jan 6, 2022 | 2.44% (0.02444) | 53.54th | v1 |
| Sep 1, 2021 | 0.56% (0.00555) | 32.58th | v1 |
| Jul 21, 2021 | 0.56% (0.00555) | 0.00th | v1 |
| Jun 30, 2021 | 0.52% (0.00524) | 0.00th | v1 |
| Jun 29, 2021 | 0.49% (0.00493) | 0.00th | v1 |
| Jun 15, 2021 | 0.46% (0.00462) | 0.00th | v1 |
| Apr 28, 2021 | 0.49% (0.00493) | 0.00th | v1 |
| Apr 27, 2021 | 2.68% (0.02678) | 0.00th | v1 |
| Apr 14, 2021 | 2.07% (0.02069) | 0.00th | v1 |
References (24)
- http://seclists.org/fulldisclosure/2021/Apr/51 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-8285 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1902687 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://curl.se/docs/CVE-2020-8285.html x_refsource_MISCVendor Advisory
- https://github.com/curl/curl/issues/6255 x_refsource_MISCExploitThird Party Advisory
- https://hackerone.com/reports/1045844 x_refsource_MISCPermissions Required
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/12/msg00029.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/ vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/ vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8285
- https://security.gentoo.org/glsa/202012-14 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210122-0007/ x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT212325 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT212326 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT212327 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8285
- https://www.debian.org/security/2021/dsa-4881 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.