vulnerability

FreeBSD: VID-3C77F139-3A09-11EB-929D-D4C9EF517024 (CVE-2020-8286): cURL -- Multiple vulnerabilities

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Dec 9, 2020
Added
Dec 10, 2020
Modified
Dec 16, 2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-3C77F139-3A09-11EB-929D-D4C9EF517024:




The cURL project reports:



Trusting FTP PASV responses (CVE-2020-8284)


FTP wildcard stack overflow (CVE-2020-8285)


Inferior OCSP verification (CVE-2020-8286)




Solution

freebsd-upgrade-package-curl
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.