CVE-2020-8177: High severity IBM Cloud Pak for Security (CP4S) vulnerability
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
Other sources
cURL could allow a remote attacker to overwrite arbitrary files on the system, caused by the improper handling of certain parameters when using -J (--remote-header-name) and -I (--include) in the same command line. An attacker could exploit this vulnerability to overwrite a local file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-8177?
CVE-2020-8177 is a vulnerability in cURL that allows a remote attacker to overwrite arbitrary files on the system.
How does CVE-2020-8177 work?
CVE-2020-8177 works by improperly handling certain parameters when using -J (--remote-header-name) and -I (--include) in the same command line, which can be exploited to overwrite a local file.
What is the severity of CVE-2020-8177?
CVE-2020-8177 has a severity rating of 7.8 (High).
Which software versions are affected by CVE-2020-8177?
Versions 7.20.0 through 7.70.0 of cURL are affected by CVE-2020-8177.
How can I fix CVE-2020-8177?
To fix CVE-2020-8177, you should update cURL to version 7.74.0-1.3+deb11u10 or later.