Unrated severityNVD Advisory· Published Jan 30, 2021· Updated Aug 4, 2024
CVE-2020-15690
CVE-2020-15690
Description
In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Nim/Nimdescription
- osv-coords5 versionspkg:rpm/opensuse/nim&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/nim&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/nim&distro=openSUSE%20Tumbleweedpkg:rpm/suse/nim&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/suse/nim&distro=SUSE%20Package%20Hub%2015%20SP4
< 1.6.6-bp153.2.3.1+ 4 more
- (no CPE)range: < 1.6.6-bp153.2.3.1
- (no CPE)range: < 1.6.6-bp154.2.3.1
- (no CPE)range: < 1.6.6-3.1
- (no CPE)range: < 1.6.6-bp153.2.3.1
- (no CPE)range: < 1.6.6-bp154.2.3.1
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2021/02/04/3mitremailing-listx_refsource_MLIST
- consensys.net/diligence/vulnerabilities/nim-asyncftpd-crlf-injection/mitrex_refsource_MISC
- github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/asyncftpclient.nimmitrex_refsource_MISC
- github.com/nim-lang/Nim/compare/v1.2.4...v1.2.6mitrex_refsource_CONFIRM
- github.com/tintinweb/pub/tree/master/pocs/cve-2020-15690mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.