cbcvebase.
CVE-2019-5436
published 2019-05-28

CVE-2019-5436: A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Affected

22 ranges
VendorProductVersion rangeFixed in
curlcurl
debiancurl< curl 7.64.0-4 (bookworm)curl 7.64.0-4 (bookworm)
debiandebian_linux
debiandebian_linux
f5traffix_signaling_delivery_controller5.0.0 – 5.1.0
fedoraprojectfedora
haxxcurl>= 0 < 7.64.0-47.64.0-4
haxxcurl>= 0 < 7.64.0-47.64.0-4
haxxcurl>= 0 < 7.64.0-47.64.0-4
haxxcurl>= 0 < 7.64.0-47.64.0-4
haxxcurl>= 0 < 7.47.0-1ubuntu2.137.47.0-1ubuntu2.13
haxxcurl>= 0 < 7.58.0-2ubuntu3.77.58.0-2ubuntu3.7
haxxcurl>= 0 < 7.35.0-1ubuntu2.20+esm27.35.0-1ubuntu2.20+esm2
haxxlibcurl7.19.4 – 7.64.1
opensuseleap
opensuseleap
opensuseleap
oracleenterprise_manager_ops_center
oracleenterprise_manager_ops_center
oraclemysql_server<= 5.7.27
oraclemysql_server5.7.28 – 8.0.17
oracleoss_support_tools

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH