CVE-2020-7450
Linux Alpine vulnerability analysis and mitigation

Overview

In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r357214, and 11.3-RELEASE before 11.3-RELEASE-p6, URL handling in libfetch with URLs containing username and/or password components is vulnerable to a heap buffer overflow. The vulnerability was discovered and disclosed in January 2020 (FreeBSD Advisory).

Technical details

The vulnerability exists in libfetch(3), a multi-protocol file transfer library included with FreeBSD and used by the fetch(1) command-line tool, pkg(8) package manager, and other components. A programming error in the library allows an attacker who can specify a URL with username and/or password components to overflow libfetch(3) buffers (FreeBSD Advisory).

Impact

An attacker in control of the URL to be fetched (possibly via HTTP redirect) may cause a heap buffer overflow, which could result in program misbehavior or malicious code execution (FreeBSD Advisory).

Mitigation and workarounds

The vulnerability was patched in FreeBSD versions after the correction date of January 28, 2020. Users should upgrade their systems to a supported FreeBSD stable or release/security branch dated after the correction date. Binary patches can be applied using the freebsd-update utility on i386 or amd64 platforms (FreeBSD Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Alpine vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13151HIGH7.5
  • Linux DebianLinux Debian
  • libtasn1
NoYesJan 07, 2026
CVE-2025-69229MEDIUM6.6
  • WolfiWolfi
  • authentik
NoYesJan 06, 2026
CVE-2025-69228MEDIUM6.6
  • WolfiWolfi
  • apache-beam-python-3.11-sdk
NoYesJan 06, 2026
CVE-2025-69227MEDIUM6.6
  • WolfiWolfi
  • open-webui
NoYesJan 06, 2026
CVE-2025-69230LOW2.7
  • WolfiWolfi
  • apache-beam-python-3.11-sdk
NoYesJan 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management