VYPR

libfetch

by FreeBSD

CVEs (2)

  • CVE-2020-7450CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.03

    In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r357214, and 11.3-RELEASE before 11.3-RELEASE-p6, URL handling in libfetch with URLs containing username and/or password components is vulnerable…

  • CVE-2021-36159CriAug 3, 2021
    risk 0.59cvss 9.1epss 0.03

    libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers into address bytes. It…