CVE-2019-5435Incorrect Calculation of Buffer Size in Curl

Severity
3.7LOWNVD
EPSS
0.2%
top 61.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 28
Latest updateJun 9

Description

An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.2 | Impact: 1.4

Affected Packages4 packages

Debianhaxx/curl< 7.64.0-4+3
Ubuntuhaxx/curl< 7.47.0-1ubuntu2.13+1
NVDhaxx/curl7.62.07.64.1
CVEListV5curl/curlFixed in 7.65.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-fp2w-w5rc-8fxj: An integer overflow in curl's URL API results in a buffer overflow in libcurl 72022-05-24
CVEList
CVE-2019-5435: An integer overflow in curl's URL API results in a buffer overflow in libcurl 72019-05-28
OSV
CVE-2019-5435: An integer overflow in curl's URL API results in a buffer overflow in libcurl 72019-05-28
OSV
curl vulnerabilities2019-05-22

📋Vendor Advisories

3
Ubuntu
curl vulnerabilities2019-05-22
Red Hat
curl: Integer overflows in curl_url_set() function2019-05-22
Debian
CVE-2019-5435: curl - An integer overflow in curl's URL API results in a buffer overflow in libcurl 7....2019

💬Community

4
HackerOne
Integer overflows in unescape_word()2022-06-09
HackerOne
CVE-2019-5435: An integer overflow found in /lib/urlapi.c2020-12-05
Bugzilla
CVE-2019-5435 curl: Integer overflows in curl_url_set() function [fedora-all]2019-05-22
Bugzilla
CVE-2019-5435 curl: Integer overflows in curl_url_set() function2019-05-15
CVE-2019-5435 — Incorrect Calculation of Buffer Size | cvebase