CVE-2019-5443
published 2019-07-02CVE-2019-5443: A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.72%
49.8th percentile
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | curl | — | — |
| haxx | curl | <= 7.65.1 | — |
| netapp | oncommand_unified_manager | >= 7.3 | — |
| netapp | oncommand_unified_manager | >= 9.5 | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | mysql_server | 5.0.0 – 5.7.27 | — |
| oracle | mysql_server | 8.0.0 – 8.0.17 | — |
| oracle | oss_support_tools | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
curl: Windows OpenSSL engine code injection
vendor_redhat·2019-06-25·CVSS 7.8
CVE-2019-5443 [HIGH] CWE-94 curl: Windows OpenSSL engine code injection
curl: Windows OpenSSL engine code injection
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
Package: rh-dotnetcore10-curl (.NET Core 1.0 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnetcore11-curl (.NET Core 1.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet21-curl (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet22-curl (.NET Core 2.2 on Red Hat Enterprise Linux) - Not affected
Package: curl (Red Hat Enterprise Linux 5) - Not affected
Package: curl (Red Hat Enterprise Linux 6) - Not affect
Debian
CVE-2019-5443: curl - A non-privileged user or program can put code and a config file in a known non-p...
vendor_debian·2019·CVSS 7.8
CVE-2019-5443 [HIGH] CVE-2019-5443: curl - A non-privileged user or program can put code and a config file in a known non-p...
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-79v3-h2vf-vcg6: A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7
ghsa_unreviewed·2022-05-24
CVE-2019-5443 [HIGH] CWE-427 GHSA-79v3-h2vf-vcg6: A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
No detection rules found.
No public exploits indexed.
HackerOne
curl on Windows can be forced to execute code via OpenSSL environment variables
hackerone·2021-02-08·CVSS 3.3
[LOW] curl on Windows can be forced to execute code via OpenSSL environment variables
curl on Windows can be forced to execute code via OpenSSL environment variables
Preface: While I have an interest in security, I am not a professional security researcher, so please be forgiving of any lack of convention in this submission. The intent is to help improve security of the OpenSSL and curl projects, their consumers and end users. I will be sending this same content to both projects, curl via hackerone, and OpenSSL via [email protected], per directions at each maintainer website.
I'm writing with regard to:
- OpenSSL CVE-2019-1552
- curl CVE-2019-5443
Background:
- The root of each of these is that a default path in the OpenSSL build system for Windows targets is a location writable by a non-privileged user, and that OpenSSL configuration files placed there can ch
Bugzilla
CVE-2019-5443 curl: Windows OpenSSL engine code injection
bugzilla·2019-11-13·CVSS 7.8
CVE-2019-5443 [HIGH] CVE-2019-5443 curl: Windows OpenSSL engine code injection
CVE-2019-5443 curl: Windows OpenSSL engine code injection
A flaw was found in all versions up to and including 7.65.1_1 of the official curl-for-windows binaries built and hosted by the curl project. A non-privileged user or program can put code and a config file in a known non-privileged path that will make curl automatically run the code on invocation.
Upstream patch:
https://github.com/curl/curl-for-win/commit/51b658a76594942cf1d6f227d8fc4732bb8ec277
References:
https://curl.haxx.se/docs/CVE-2019-5443.html
Discussion:
Acknowledgments:
Name: the Curl project
Upstream: Rich Mirch
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-5443
HackerOne
Windows builds with insecure path defaults (CVE-2019-1552)
hackerone·2019-09-24·CVSS 3.3
CVE-2019-1552 [LOW] Windows builds with insecure path defaults (CVE-2019-1552)
Windows builds with insecure path defaults (CVE-2019-1552)
Advisory: https://www.openssl.org/news/secadv/20190730.txt
```
Severity: Low
OpenSSL has internal defaults for a directory tree where it can find a
configuration file as well as certificates used for verification in
TLS. This directory is most commonly referred to as OPENSSLDIR, and
is configurable with the --prefix / --openssldir configuration options.
For OpenSSL versions 1.1.0 and 1.1.1, the mingw configuration targets
assume that resulting programs and libraries are installed in a
Unix-like environment and the default prefix for program installation
as well as for OPENSSLDIR should be '/usr/local'.
However, mingw programs are Windows programs, and as such, find
themselves looking at sub-directories of 'C:/usr/local', which
Bugzilla
CVE-2019-10211 postgresql: Windows installer bundled OpenSSL executes code from unprotected directory
bugzilla·2019-07-30·CVSS 9.8
CVE-2019-10211 [CRITICAL] CVE-2019-10211 postgresql: Windows installer bundled OpenSSL executes code from unprotected directory
CVE-2019-10211 postgresql: Windows installer bundled OpenSSL executes code from unprotected directory
When the database server or libpq client library initializes SSL, libeay32.dll
attempts to read configuration from a hard-coded directory. Typically, the
directory does not exist, but any local user could create it and inject
configuration. This configuration can direct OpenSSL to load and execute
arbitrary code as the user running a PostgreSQL server or client. Most
PostgreSQL client tools and libraries use libpq, and one can encounter this
vulnerability by using any of them. This vulnerability is much like
CVE-2019-5443, but it originated independently. One can work around the
vulnerability by setting environment variable OPENSSL_CONF to
"NUL:/openssl.cnf" or any other name that cannot
HackerOne
CVE-2019-5443: Windows Privilege Escalation: Malicious OpenSSL Engine
hackerone·2019-06-29·CVSS 7.8
CVE-2019-5443 [HIGH] CVE-2019-5443: Windows Privilege Escalation: Malicious OpenSSL Engine
CVE-2019-5443: Windows Privilege Escalation: Malicious OpenSSL Engine
## Summary:
The curl windows binaries are built with OpenSSL libraries and have an insecure path for the OPENSSLDIR build parameter. This path is set to c:\usr\local\ssl. When curl is executed it attempts to load openssl.cnf from this path. By default on windows, low privileged users have the authority to create folders under c:\. A low privileged user can create a custom openssl.cnf file to load a malicious OpenSSL Engine(library). The result is arbitrary code execution with the full authority of the account executing the curl binary.
Version tested.
curl-7.65.1_1-win64
OS:
Windows 10
## Steps To Reproduce:
All steps are executed as a low privileged(non-admin) user unless otherwise noted
1. As a low privileged use
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
http://www.openwall.com/lists/oss-security/2019/06/24/1http://www.securityfocus.com/bid/108881https://curl.haxx.se/docs/CVE-2019-5443.htmlhttps://security.netapp.com/advisory/ntap-20191017-0002/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://www.openwall.com/lists/oss-security/2019/06/24/1http://www.securityfocus.com/bid/108881https://curl.haxx.se/docs/CVE-2019-5443.htmlhttps://security.netapp.com/advisory/ntap-20191017-0002/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-07-02
Published