UBUNTU-CVE-2020-8284

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2020-8284
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-8284.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2020-8284
Related
Published
2020-12-09T08:00:00Z
Modified
2020-12-09T08:00:00Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

References

Affected packages

Ubuntu:Pro:14.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl@7.35.0-1ubuntu2.20+esm6?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.35.0-1ubuntu2.20+esm6

Affected versions

7.*

7.32.0-1ubuntu1
7.33.0-1ubuntu1
7.34.0-1ubuntu1
7.35.0-1ubuntu1
7.35.0-1ubuntu2
7.35.0-1ubuntu2.1
7.35.0-1ubuntu2.2
7.35.0-1ubuntu2.3
7.35.0-1ubuntu2.5
7.35.0-1ubuntu2.6
7.35.0-1ubuntu2.7
7.35.0-1ubuntu2.8
7.35.0-1ubuntu2.9
7.35.0-1ubuntu2.10
7.35.0-1ubuntu2.11
7.35.0-1ubuntu2.12
7.35.0-1ubuntu2.13
7.35.0-1ubuntu2.14
7.35.0-1ubuntu2.15
7.35.0-1ubuntu2.16
7.35.0-1ubuntu2.17
7.35.0-1ubuntu2.19
7.35.0-1ubuntu2.20
7.35.0-1ubuntu2.20+esm3
7.35.0-1ubuntu2.20+esm4
7.35.0-1ubuntu2.20+esm5

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "curl-udeb": "7.35.0-1ubuntu2.20+esm6",
            "libcurl3": "7.35.0-1ubuntu2.20+esm6",
            "libcurl4-gnutls-dev": "7.35.0-1ubuntu2.20+esm6",
            "libcurl3-dbgsym": "7.35.0-1ubuntu2.20+esm6",
            "libcurl3-nss": "7.35.0-1ubuntu2.20+esm6",
            "libcurl4-doc": "7.35.0-1ubuntu2.20+esm6",
            "libcurl3-udeb-dbgsym": "7.35.0-1ubuntu2.20+esm6",
            "libcurl3-gnutls-dbgsym": "7.35.0-1ubuntu2.20+esm6",
            "libcurl4-openssl-dev": "7.35.0-1ubuntu2.20+esm6",
            "libcurl4-openssl-dev-dbgsym": "7.35.0-1ubuntu2.20+esm6",
            "curl-dbgsym": "7.35.0-1ubuntu2.20+esm6",
            "curl": "7.35.0-1ubuntu2.20+esm6",
            "libcurl3-udeb": "7.35.0-1ubuntu2.20+esm6",
            "curl-udeb-dbgsym": "7.35.0-1ubuntu2.20+esm6",
            "libcurl4-nss-dev-dbgsym": "7.35.0-1ubuntu2.20+esm6",
            "libcurl3-gnutls": "7.35.0-1ubuntu2.20+esm6",
            "libcurl4-gnutls-dev-dbgsym": "7.35.0-1ubuntu2.20+esm6",
            "libcurl3-nss-dbgsym": "7.35.0-1ubuntu2.20+esm6",
            "libcurl3-dbg": "7.35.0-1ubuntu2.20+esm6",
            "libcurl4-nss-dev": "7.35.0-1ubuntu2.20+esm6"
        }
    ]
}

Ubuntu:16.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl@7.47.0-1ubuntu2.18?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.47.0-1ubuntu2.18

Affected versions

7.*

7.43.0-1ubuntu2
7.45.0-1ubuntu1
7.46.0-1ubuntu1
7.47.0-1ubuntu1
7.47.0-1ubuntu2
7.47.0-1ubuntu2.1
7.47.0-1ubuntu2.2
7.47.0-1ubuntu2.3
7.47.0-1ubuntu2.4
7.47.0-1ubuntu2.5
7.47.0-1ubuntu2.6
7.47.0-1ubuntu2.7
7.47.0-1ubuntu2.8
7.47.0-1ubuntu2.9
7.47.0-1ubuntu2.11
7.47.0-1ubuntu2.12
7.47.0-1ubuntu2.13
7.47.0-1ubuntu2.14
7.47.0-1ubuntu2.15
7.47.0-1ubuntu2.16

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "libcurl3": "7.47.0-1ubuntu2.18",
            "libcurl4-gnutls-dev": "7.47.0-1ubuntu2.18",
            "libcurl3-dbgsym": "7.47.0-1ubuntu2.18",
            "libcurl3-nss": "7.47.0-1ubuntu2.18",
            "libcurl4-doc": "7.47.0-1ubuntu2.18",
            "libcurl3-gnutls-dbgsym": "7.47.0-1ubuntu2.18",
            "libcurl4-openssl-dev": "7.47.0-1ubuntu2.18",
            "libcurl4-openssl-dev-dbgsym": "7.47.0-1ubuntu2.18",
            "curl-dbgsym": "7.47.0-1ubuntu2.18",
            "curl": "7.47.0-1ubuntu2.18",
            "libcurl4-nss-dev-dbgsym": "7.47.0-1ubuntu2.18",
            "libcurl3-gnutls": "7.47.0-1ubuntu2.18",
            "libcurl4-gnutls-dev-dbgsym": "7.47.0-1ubuntu2.18",
            "libcurl3-nss-dbgsym": "7.47.0-1ubuntu2.18",
            "libcurl3-dbg": "7.47.0-1ubuntu2.18",
            "libcurl4-nss-dev": "7.47.0-1ubuntu2.18"
        }
    ]
}

Ubuntu:18.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl@7.58.0-2ubuntu3.12?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.58.0-2ubuntu3.12

Affected versions

7.*

7.55.1-1ubuntu2
7.55.1-1ubuntu2.1
7.57.0-1ubuntu1
7.58.0-2ubuntu1
7.58.0-2ubuntu2
7.58.0-2ubuntu3
7.58.0-2ubuntu3.1
7.58.0-2ubuntu3.2
7.58.0-2ubuntu3.3
7.58.0-2ubuntu3.5
7.58.0-2ubuntu3.6
7.58.0-2ubuntu3.7
7.58.0-2ubuntu3.8
7.58.0-2ubuntu3.9
7.58.0-2ubuntu3.10

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "curl-dbgsym": "7.58.0-2ubuntu3.12",
            "curl": "7.58.0-2ubuntu3.12",
            "libcurl4": "7.58.0-2ubuntu3.12",
            "libcurl4-gnutls-dev": "7.58.0-2ubuntu3.12",
            "libcurl4-dbgsym": "7.58.0-2ubuntu3.12",
            "libcurl3-nss": "7.58.0-2ubuntu3.12",
            "libcurl4-doc": "7.58.0-2ubuntu3.12",
            "libcurl3-nss-dbgsym": "7.58.0-2ubuntu3.12",
            "libcurl3-gnutls": "7.58.0-2ubuntu3.12",
            "libcurl3-gnutls-dbgsym": "7.58.0-2ubuntu3.12",
            "libcurl4-openssl-dev": "7.58.0-2ubuntu3.12",
            "libcurl4-nss-dev": "7.58.0-2ubuntu3.12"
        }
    ]
}

Ubuntu:20.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl@7.68.0-1ubuntu2.4?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.68.0-1ubuntu2.4

Affected versions

7.*

7.65.3-1ubuntu3
7.65.3-1ubuntu4
7.66.0-1ubuntu1
7.67.0-2ubuntu1
7.68.0-1ubuntu1
7.68.0-1ubuntu2
7.68.0-1ubuntu2.1
7.68.0-1ubuntu2.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "curl-dbgsym": "7.68.0-1ubuntu2.4",
            "curl": "7.68.0-1ubuntu2.4",
            "libcurl4": "7.68.0-1ubuntu2.4",
            "libcurl4-gnutls-dev": "7.68.0-1ubuntu2.4",
            "libcurl4-dbgsym": "7.68.0-1ubuntu2.4",
            "libcurl3-nss": "7.68.0-1ubuntu2.4",
            "libcurl4-doc": "7.68.0-1ubuntu2.4",
            "libcurl3-nss-dbgsym": "7.68.0-1ubuntu2.4",
            "libcurl3-gnutls": "7.68.0-1ubuntu2.4",
            "libcurl3-gnutls-dbgsym": "7.68.0-1ubuntu2.4",
            "libcurl4-openssl-dev": "7.68.0-1ubuntu2.4",
            "libcurl4-nss-dev": "7.68.0-1ubuntu2.4"
        }
    ]
}