Uncontrolled Recursion in cURL - CVE-2020-8285

 

Uncontrolled Recursion in cURL - CVE-2020-8285

Published: December 9, 2020 / Updated: October 28, 2023


Vulnerability identifier: #VU48894
CSH Severity: Low
CVSS v4 BT: 1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2020-8285
CWE-ID: CWE-674
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due tu uncontrolled recursion when processing FTP responses within the wildcard matching functionality, which allows a callback (set with <a href="https://curl.se/libcurl/c/CURLOPT_CHUNK_BGN_FUNCTION.html">CURLOPT_CHUNK_BGN_FUNCTION</a>) to return information back to libcurl on how to handle a specific entry in a directory when libcurl iterates over a list of all available entries. A remote attacker who controls the malicious FTP server can trick the victim to connect to it and crash the application, which is using the affected libcurl version.


Affected software

cURL
Cloud Pak for Security (CP4S)
Gentoo Linux
ClevOS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
macOS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
Ubuntu
Slackware Linux
Junos OS
openEuler
Junos OS Evolved
Fedora
Fujitsu M10-4
Fujitsu M10-4S
Fujitsu M10-1
Secured Component Verification (SCV)
Fujitsu M12-1
Fujitsu M12-2
Fujitsu M12-2S
BIG-IP
BIG-IP SSLO
BIG-IP DDHD
curl (Alpine package)
jbcs-httpd24 (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
curl (Red Hat package)
curl (Debian package)
jbcs-httpd24-curl (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
curl (Ubuntu package)
libcurl3 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl4-32bit
libcurl4-debuginfo
curl
curl-debuginfo
curl-debugsource
libcurl4
libcurl4-debuginfo-32bit
libcurl-devel
curl-help
libcurl
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
TensorFlow
Red Hat OpenShift Jaeger
Traffix SDC
Splunk Universal Forwarder
Splunk Enterprise
GitLab Enterprise Edition
Gitlab Community Edition
BIG-IP ASM
BIG-IP AFM
BIG-IP Analytics
BIG-IP FPS
BIG-IP GTM
BIG-IP APM
BIG-IP PEM
BIG-IP LTM
BIG-IP Advanced WAF
BIG-IP Link Controller
BIG-IP AAM
BIG-IP DNS
Oracle Essbase
SINEC INS
Web Terminal
JBoss Core Services

How to mitigate CVE-2020-8285

Install updates from vendor's website.

cURL - update to 7.74.0
Red Hat OpenShift Serverless - update to 1.16.0
TensorFlow - update to 2.5.0
jbcs-httpd24 (Red Hat package) - addressed in versions 1-18.el8jbcs, 1-18.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-82.el8jbcs, 1.6.1-82.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-105.el8jbcs, 1.6.3-105.jbcs.el7
Cloud Pak for Security (CP4S) - update to 1.8.0.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-17.el8jbcs, 1.15.7-17.jbcs.el7
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-36.el8jbcs, 2.0.8-36.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-74.el8jbcs, 2.4.37-74.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-63.GA.el8jbcs, 2.9.2-63.GA.jbcs.el7
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.11-55.el8jbcs, 2.11-55.jbcs.el7
curl (Alpine package) - update to 7.74.0-r0
curl (Red Hat package) - update to 7.61.1-18.el8
curl (Debian package) - update to 7.64.0-4+deb10u2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.77.0-2.el8jbcs, 7.77.0-2.jbcs.el7
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - addressed in versions 10.14.6 18G9028, 10.15.7 19H1030, 11.3 20E232
GitLab Enterprise Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2
Gitlab Community Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2
Junos OS - addressed in versions 15.1R7-S9, 17.3R3-S12, 17.4R3-S5, 18.1R3-S13, 18.3R3-S5, 18.4R2-S9, 18.4R3-S9, 19.1R3-S5, 19.2R3-S2, 19.3R2-S6, 19.3R3-S2, 19.4R1-S4, 19.4R2-S4, 19.4R3-S3, 20.1R2-S2, 20.1R3, 20.2R2-S3, 20.2R3, 20.3R2, 20.4R1-S1, 20.4R2, 21.1R1, 23.4R1-S1, 23.4R2, 24.1R1
Junos OS Evolved - addressed in versions 20.4R2-EVO, 21.1R1-EVO, 21.4R3-S4-EVO, 22.1R3-S4-EVO, 22.3R3-S1-EVO, 22.4R2-S1-EVO, 23.2R1-EVO
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-20.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-5.el8jbcs
SINEC INS - update to 1.0.1.1
jbcs-httpd24-brotli (Red Hat package) - update to 1.0.6-40.el8jbcs
Web Terminal - update to 1.3
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-37.el8jbcs
Secured Component Verification (SCV) - update to 1.92.0
JBoss Core Services - update to 2.4.37 SP8
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
curl (Ubuntu package) - addressed in versions 7.22.0-3ubuntu4.29, 7.35.0-1ubuntu2.20+esm6, 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl3 (Ubuntu package) - addressed in versions 7.22.0-3ubuntu4.29, 7.35.0-1ubuntu2.20+esm6, 7.47.0-1ubuntu2.18
libcurl3-nss (Ubuntu package) - addressed in versions 7.22.0-3ubuntu4.29, 7.35.0-1ubuntu2.20+esm6, 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.22.0-3ubuntu4.29, 7.35.0-1ubuntu2.20+esm6, 7.47.0-1ubuntu2.18, 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.12, 7.68.0-1ubuntu2.4, 7.68.0-1ubuntu4.2
libcurl4-32bit - update to 7.60.0-4.20.1
libcurl4-debuginfo - update to 7.60.0-4.20.1
curl - update to 7.60.0-4.20.1
curl-debuginfo - update to 7.60.0-4.20.1
curl-debugsource - update to 7.60.0-4.20.1
libcurl4 - update to 7.60.0-4.20.1
libcurl4-debuginfo-32bit - update to 7.60.0-4.20.1
curl - addressed in versions 7.69.1-7.fc32, 7.71.1-8.fc33
libcurl-devel - update to 7.71.1-5
curl - update to 7.71.1-5
curl-help - update to 7.71.1-5
curl-debuginfo - update to 7.71.1-5
libcurl - update to 7.71.1-5
curl-debugsource - update to 7.71.1-5

External References

Related Security Bulletins