CVE-2019-5436
published 2019-05-28CVE-2019-5436: A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
PriorityP356high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
49.74%
98.8th percentile
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | — | — |
| debian | curl | < curl 7.64.0-4 (bookworm) | curl 7.64.0-4 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| f5 | traffix_signaling_delivery_controller | 5.0.0 – 5.1.0 | — |
| fedoraproject | fedora | — | — |
| haxx | curl | >= 0 < 7.64.0-4 | 7.64.0-4 |
| haxx | curl | >= 0 < 7.64.0-4 | 7.64.0-4 |
| haxx | curl | >= 0 < 7.64.0-4 | 7.64.0-4 |
| haxx | curl | >= 0 < 7.64.0-4 | 7.64.0-4 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.13 | 7.47.0-1ubuntu2.13 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.7 | 7.58.0-2ubuntu3.7 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20+esm2 | 7.35.0-1ubuntu2.20+esm2 |
| haxx | libcurl | 7.19.4 – 7.64.1 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | mysql_server | <= 5.7.27 | — |
| oracle | mysql_server | 5.7.28 – 8.0.17 | — |
| oracle | oss_support_tools | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
curl vulnerabilities
vendor_ubuntu·2019-05-22·CVSS 3.7
CVE-2019-5435 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Wenchao Li discovered that curl incorrectly handled memory in the
curl_url_set() function. A remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 19.04. (CVE-2019-5435)
It was discovered that curl incorrectly handled memory when receiving data
from a TFTP server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2019-5436)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerability
vendor_ubuntu·2019-05-22·CVSS 7.8
CVE-2019-5436 [HIGH] curl vulnerability
Title: curl vulnerability
Summary: curl could be made to crash if it received a specially crafted data.
USN-3993-1 fixed a vulnerability in curl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that curl incorrectly handled memory when receiving data
from a TFTP server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2019-5436)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: TFTP receive heap buffer overflow in tftp_receive_packet() function
vendor_redhat·2019-05-22·CVSS 7.8
CVE-2019-5436 [HIGH] CWE-122 curl: TFTP receive heap buffer overflow in tftp_receive_packet() function
curl: TFTP receive heap buffer overflow in tftp_receive_packet() function
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
Statement: This flaw exists if the user selects to use a "blksize" of 504 or smaller (default is 512). The smaller size that is used, the larger the possible overflow becomes.
Users choosing a smaller size than default should be rare as the primary use case for changing the size is to make it larger. It is rare for users to use TFTP across the Internet. It is most commonly used within local networks.
Package: rh-dotnetcore10-curl (.NET Core 1.0 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnetcore11-curl (.NET Core 1.1 on Red Hat Enterprise Linux) - Not affected
Pac
Debian
CVE-2019-5436: curl - A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary co...
vendor_debian·2019·CVSS 7.8
CVE-2019-5436 [HIGH] CVE-2019-5436: curl - A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary co...
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
Scope: local
bookworm: resolved (fixed in 7.64.0-4)
bullseye: resolved (fixed in 7.64.0-4)
forky: resolved (fixed in 7.64.0-4)
sid: resolved (fixed in 7.64.0-4)
trixie: resolved (fixed in 7.64.0-4)
VulDB
libcURL up to 7.64.1 tftp memory corruption (K55133295 / Nessus ID 236591)
vuldb·2026-04-16·CVSS 7.8
CVE-2019-5436 [HIGH] libcURL up to 7.64.1 tftp memory corruption (K55133295 / Nessus ID 236591)
A vulnerability was found in libcURL up to 7.64.1. It has been rated as critical. This issue affects some unknown processing of the component tftp. This manipulation causes memory corruption.
This vulnerability is tracked as CVE-2019-5436. The attack is restricted to local execution. No exploit exists.
GHSA
GHSA-8xvc-p9x4-w7jm: A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7
ghsa_unreviewed·2022-05-24
CVE-2019-5436 [HIGH] CWE-122 GHSA-8xvc-p9x4-w7jm: A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
OSV
CVE-2019-5436: A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7
osv·2019-05-28·CVSS 7.8
CVE-2019-5436 [HIGH] CVE-2019-5436: A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
OSV
curl vulnerability
osv·2019-05-22·CVSS 7.8
CVE-2019-5436 [HIGH] curl vulnerability
curl vulnerability
USN-3993-1 fixed a vulnerability in curl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that curl incorrectly handled memory when receiving data
from a TFTP server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2019-5436)
OSV
curl vulnerabilities
osv·2019-05-22·CVSS 3.7
CVE-2019-5435 [LOW] curl vulnerabilities
curl vulnerabilities
Wenchao Li discovered that curl incorrectly handled memory in the
curl_url_set() function. A remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 19.04. (CVE-2019-5435)
It was discovered that curl incorrectly handled memory when receiving data
from a TFTP server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2019-5436)
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2019-5482: Heap buffer overflow in TFTP when using small blksize
hackerone·2020-11-14·CVSS 7.8
CVE-2019-5482 [HIGH] CVE-2019-5482: Heap buffer overflow in TFTP when using small blksize
CVE-2019-5482: Heap buffer overflow in TFTP when using small blksize
## Summary:
With a TFTP server that does not send OACK, but instead starts anyway with first block with 512 bytes block size, the curl library fails to assume default 512 bytes blocks. Instead it detects EOF and does not return an error code. Consequence is a truncated file that is 512 bytes without any error code.
My understanding is that from the RFC, a TFTP server might ignore blksize request and anyway send the default 512 bytes block size data.
Unless an OACK is received we should assume 512 block size, whether or not a particular blocksize was requested.
This was introduced by security fix of CVE-2019-5436:
257600341 tftp: use the current blksize for recvfrom()
## Potential Fix
We could revert 2576003415625d7b5
Bugzilla
CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet()
bugzilla·2019-09-06·CVSS 7.8
CVE-2019-5482 [HIGH] CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet()
CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet()
A vulnerability was found in libcurl contains a heap buffer overflow in the function ('tftp_receive_packet()') that receives data from a TFTP server. It can call 'recvfrom()' with the default size for the buffer rather than with the size that was used to allocate it. Thus, the content that might overwrite the heap memory is controlled by the server.
Discussion:
Acknowledgments:
Name: the Curl project
Upstream: Thomas Vegas
---
What is the impact and cvss score for this issue?
https://access.redhat.com/security/cve/CVE-2019-5482 gives me 404.
---
Upstream patch: https://github.com/curl/curl/commit/facb0e4662415b5f28163e853dc6742ac5fafb3d
This flaw was introduced in January 2009 via https://github.com/curl/c
HackerOne
CVE-2019-5436: Heap Buffer Overflow at lib/tftp.c
hackerone·2019-05-31·CVSS 7.8
CVE-2019-5436 [HIGH] CVE-2019-5436: Heap Buffer Overflow at lib/tftp.c
CVE-2019-5436: Heap Buffer Overflow at lib/tftp.c
## Summary:
A heap buffer overflow can occur at line 1114 in file `lib/tftp.c` due to the fact of `state->blksize` containing the default size instead of containing the one specified in the `--tftp-blksize` parameter.
This bug could lead to a **crash** or maybe to **RCE** in the case the attacker also had a memory leak.
### Vulnerable line:
```
state->rbytes = (int)recvfrom(state->sockfd,
(void *)state->rpacket.data,
state->blksize + 4,
0,
(struct sockaddr *)&fromaddr,
&fromlen);
```
## Steps To Reproduce:
1. Download the server script
1. Run it and bind to an address: `$ python evil-server.py IP PORT`
1. Connect to that server with curl: `$ curl --tftp-blksize N tftp://IP:PORT`
Where **N** should be a number lower than 293.
## Impa
Bugzilla
CVE-2019-5436 curl: TFTP receive heap buffer overflow in tftp_receive_packet() function [fedora-all]
bugzilla·2019-05-22·CVSS 7.8
CVE-2019-5436 [HIGH] CVE-2019-5436 curl: TFTP receive heap buffer overflow in tftp_receive_packet() function [fedora-all]
CVE-2019-5436 curl: TFTP receive heap buffer overflow in tftp_receive_packet() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2019-5436 curl: TFTP receive heap buffer overflow in tftp_receive_packet() function
bugzilla·2019-05-15·CVSS 7.8
CVE-2019-5436 [HIGH] CVE-2019-5436 curl: TFTP receive heap buffer overflow in tftp_receive_packet() function
CVE-2019-5436 curl: TFTP receive heap buffer overflow in tftp_receive_packet() function
libcurl contains a heap buffer overflow in the function (`tftp_receive_packet()`) that recevives data from a TFTP server. It calls `recvfrom()` with the default size for the buffer rather than with the size that was used to allocate it. Thus, the content that might overwrite the heap memory is entirely controlled by the server.
Upstream patch:
https://curl.haxx.se/0001-tftp-use-the-current-blksize-for-recvfrom.patch
References:
https://curl.haxx.se/docs/CVE-2019-5436.html
Discussion:
libcurl contains a heap buffer overflow in the function (`tftp_receive_packet()`) that recevives data from a TFTP server. It calls `recvfrom()` with the default size for the buffer rather than with the size that was
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00017.htmlhttp://www.openwall.com/lists/oss-security/2019/09/11/6https://curl.haxx.se/docs/CVE-2019-5436.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMG3V4VTX2SE3EW3HQTN3DDLQBTORQC2/https://seclists.org/bugtraq/2020/Feb/36https://security.gentoo.org/glsa/202003-29https://security.netapp.com/advisory/ntap-20190606-0004/https://support.f5.com/csp/article/K55133295https://support.f5.com/csp/article/K55133295?utm_source=f5support&%3Butm_medium=RSShttps://www.debian.org/security/2020/dsa-4633https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00017.htmlhttp://www.openwall.com/lists/oss-security/2019/09/11/6https://curl.haxx.se/docs/CVE-2019-5436.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMG3V4VTX2SE3EW3HQTN3DDLQBTORQC2/https://seclists.org/bugtraq/2020/Feb/36https://security.gentoo.org/glsa/202003-29https://security.netapp.com/advisory/ntap-20190606-0004/https://support.f5.com/csp/article/K55133295https://support.f5.com/csp/article/K55133295?utm_source=f5support&%3Butm_medium=RSShttps://www.debian.org/security/2020/dsa-4633https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-05-28
Published