PT-2020-6190 · Curl+9 · Curl+9

Published

2020-11-21

·

Updated

2026-05-18

·

CVE-2020-8284

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions curl versions 7.73.0 and earlier
Description A malicious server can use the FTP PASV response to trick curl into connecting back to a given IP address and port, potentially making curl extract information about services that are otherwise private and not disclosed. This could allow for port scanning and service banner extractions. The issue arises when curl performs a passive FTP transfer, first trying the EPSV command and falling back to PASV if not supported. A server response to a PASV command includes the address and port number for the client to connect back to, which a malicious server can exploit.
Recommendations For curl versions 7.73.0 and earlier, consider updating to a version with improved checks to address this issue. As a temporary workaround, restrict the use of curl with untrusted FTP servers to minimize the risk of exploitation. Avoid using curl with URLs provided by untrusted users to prevent potential attacks.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3572
ALT-PU-2020-3573
ALT-PU-2021-1592
BDU:2021-03504
CESA-2021_1610
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2020-8284
DLA-2500-1
DLA-3205-1
DSA-4881-1
MGASA-2020-0482
OESA-2021-1004
OPENSUSE-SU-2020:2238-1
OPENSUSE-SU-2020:2249-1
OPENSUSE-SU-2020_2238-1
OPENSUSE-SU-2020_2249-1
OPENSUSE-SU-2024:10582-1
RHSA-2021:1610
RHSA-2021:2472
RHSA-2021_1610
RLSA-2021:1610
SUSE-SU-2020:14585-1
SUSE-SU-2020:3733-1
SUSE-SU-2020:3735-1
SUSE-SU-2020:3739-1
SUSE-SU-2020_14585-1
SUSE-SU-2020_3733-1
SUSE-SU-2020_3735-1
SUSE-SU-2020_3739-1
SUSE-SU-2021:1786-1
USN-4665-1
USN-4665-2

Affected Products

Alt Linux
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Suse
Ubuntu
Curl