CVE-2019-5482
published 2019-09-16CVE-2019-5482: Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.94%
96.8th percentile
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | curl | < curl 7.66.0-1 (bookworm) | curl 7.66.0-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| haxx | curl | — | — |
| haxx | curl | >= 0 < 7.66.0-1 | 7.66.0-1 |
| haxx | curl | >= 0 < 7.66.0-1 | 7.66.0-1 |
| haxx | curl | >= 0 < 7.66.0-1 | 7.66.0-1 |
| haxx | curl | >= 0 < 7.66.0-1 | 7.66.0-1 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.14 | 7.47.0-1ubuntu2.14 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.8 | 7.58.0-2ubuntu3.8 |
| haxx | curl | 7.19.4 – 7.65.3 | — |
| netapp | oncommand_unified_manager | >= 7.3 | — |
| netapp | oncommand_unified_manager | >= 9.5 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | communications_session_border_controller | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
cURL up to 7.65.3 TFTP Protocol buffer overflow (FEDORA-2019-6d7f6fa2c8 / Nessus ID 236591)
vuldb·2026-04-16·CVSS 9.8
CVE-2019-5482 [CRITICAL] cURL up to 7.65.3 TFTP Protocol buffer overflow (FEDORA-2019-6d7f6fa2c8 / Nessus ID 236591)
A vulnerability, which was classified as critical, has been found in cURL up to 7.65.3. Affected is an unknown function of the component TFTP Protocol Handler. This manipulation causes buffer overflow.
This vulnerability is tracked as CVE-2019-5482. The attack is possible to be carried out remotely. No exploit exists.
VulDB
Oracle Communications Operations Monitor up to 4.3.0 REST API buffer overflow (Nessus ID 236591)
vuldb·2026-04-16·CVSS 9.8
CVE-2019-5482 [CRITICAL] Oracle Communications Operations Monitor up to 4.3.0 REST API buffer overflow (Nessus ID 236591)
A vulnerability was found in Oracle Communications Operations Monitor 3.4.0/4.0.0/4.1.0/4.2.0/4.3.0. It has been classified as very critical. This impacts an unknown function of the component REST API. The manipulation leads to buffer overflow.
This vulnerability is referenced as CVE-2019-5482. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
VulDB
Oracle OSS Support Tools 20 Services Tools Bundle buffer overflow (Nessus ID 236591)
vuldb·2026-04-16·CVSS 9.8
CVE-2019-5482 [CRITICAL] Oracle OSS Support Tools 20 Services Tools Bundle buffer overflow (Nessus ID 236591)
A vulnerability was found in Oracle OSS Support Tools 20 and classified as very critical. The affected element is an unknown function of the component Services Tools Bundle. The manipulation results in buffer overflow.
This vulnerability is cataloged as CVE-2019-5482. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle MySQL Server up to 5.7.28/8.0.18 Compiling buffer overflow (Nessus ID 236591)
vuldb·2026-04-16·CVSS 9.8
CVE-2019-5482 [CRITICAL] Oracle MySQL Server up to 5.7.28/8.0.18 Compiling buffer overflow (Nessus ID 236591)
A vulnerability marked as very critical has been reported in Oracle MySQL Server up to 5.7.28/8.0.18. This vulnerability affects unknown code of the component Compiling. The manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2019-5482. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
VulDB
Oracle Hyperion Essbase 11.1.2.4 Security/Provisioning buffer overflow (Nessus ID 236591)
vuldb·2026-04-16·CVSS 9.8
CVE-2019-5482 [CRITICAL] Oracle Hyperion Essbase 11.1.2.4 Security/Provisioning buffer overflow (Nessus ID 236591)
A vulnerability has been found in Oracle Hyperion Essbase 11.1.2.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Security/Provisioning. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2019-5482. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
VulDB
Oracle HTTP Server 12.2.1.3.0/12.2.1.4.0 Web Listener buffer overflow (Nessus ID 236591)
vuldb·2026-04-16·CVSS 9.8
CVE-2019-5482 [CRITICAL] Oracle HTTP Server 12.2.1.3.0/12.2.1.4.0 Web Listener buffer overflow (Nessus ID 236591)
A vulnerability marked as critical has been reported in Oracle HTTP Server 12.2.1.3.0/12.2.1.4.0. The impacted element is an unknown function of the component Web Listener. The manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2019-5482. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Enterprise Manager Ops Center 12.3.3/12.4.0 Networking buffer overflow (Nessus ID 236591)
vuldb·2026-04-16·CVSS 9.8
CVE-2019-5482 [CRITICAL] Oracle Enterprise Manager Ops Center 12.3.3/12.4.0 Networking buffer overflow (Nessus ID 236591)
A vulnerability was found in Oracle Enterprise Manager Ops Center 12.3.3/12.4.0. It has been classified as very critical. This affects an unknown part of the component Networking. Performing a manipulation results in buffer overflow.
This vulnerability is known as CVE-2019-5482. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-35cc-32cj-vr6g: Heap buffer overflow in the TFTP protocol handler in cURL 7
ghsa_unreviewed·2022-05-24
CVE-2019-5482 [CRITICAL] CWE-122 GHSA-35cc-32cj-vr6g: Heap buffer overflow in the TFTP protocol handler in cURL 7
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
OSV
CVE-2019-5482: Heap buffer overflow in the TFTP protocol handler in cURL 7
osv·2019-09-16·CVSS 9.8
CVE-2019-5482 [CRITICAL] CVE-2019-5482: Heap buffer overflow in the TFTP protocol handler in cURL 7
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
OSV
curl vulnerabilities
osv·2019-09-11·CVSS 9.8
CVE-2019-5481 [CRITICAL] curl vulnerabilities
curl vulnerabilities
Thomas Vegas discovered that curl incorrectly handled memory when using
Kerberos over FTP. A remote attacker could use this issue to crash curl,
resulting in a denial of service. (CVE-2019-5481)
Thomas Vegas discovered that curl incorrectly handled memory during TFTP
transfers. A remote attacker could use this issue to crash curl, resulting
in a denial of service, or possibly execute arbitrary code. (CVE-2019-5482)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Listener (cURL) — CVE-2019-5482
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2019-5482 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Web Listener (cURL) — CVE-2019-5482
Oracle Oracle Fusion Middleware Risk Matrix: Web Listener (cURL) vulnerability
CVE: CVE-2019-5482
CVSS: 9.8
Protocol: TFTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: REST API (cURL) — CVE-2019-5482
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2019-5482 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: REST API (cURL) — CVE-2019-5482
Oracle Oracle Communications Applications Risk Matrix: REST API (cURL) vulnerability
CVE: CVE-2019-5482
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Networking (cURL) — CVE-2019-5482
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2019-5482 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Networking (cURL) — CVE-2019-5482
Oracle Oracle Enterprise Manager Risk Matrix: Networking (cURL) vulnerability
CVE: CVE-2019-5482
CVSS: 9.8
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Ubuntu
curl vulnerability
vendor_ubuntu·2019-09-12
CVE-2019-5482 curl vulnerability
Title: curl vulnerability
Summary: curl could be made to crash or possibly execute arbitrary code
if it incorrectly handled memory during TFTP transfers.
USN-4129-1 fixed a vulnerability in curl. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.
Original advisory details:
Thomas Vegas discovered that curl incorrectly handled memory during TFTP
transfers. A remote attacker could use this issue to crash curl, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2019-09-11·CVSS 9.8
CVE-2019-5481 [CRITICAL] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Thomas Vegas discovered that curl incorrectly handled memory when using
Kerberos over FTP. A remote attacker could use this issue to crash curl,
resulting in a denial of service. (CVE-2019-5481)
Thomas Vegas discovered that curl incorrectly handled memory during TFTP
transfers. A remote attacker could use this issue to crash curl, resulting
in a denial of service, or possibly execute arbitrary code. (CVE-2019-5482)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: heap buffer overflow in function tftp_receive_packet()
vendor_redhat·2019-09-11·CVSS 9.8
CVE-2019-5482 [CRITICAL] CWE-122 curl: heap buffer overflow in function tftp_receive_packet()
curl: heap buffer overflow in function tftp_receive_packet()
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
Mitigation: Do not use TFTP with curl with smaller than the default BLKSIZE.
Package: rh-dotnet21-curl (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet22-curl (.NET Core 2.2 on Red Hat Enterprise Linux) - Not affected
Package: curl (Red Hat Enterprise Linux 5) - Not affected
Package: curl (Red Hat Enterprise Linux 6) - Out of support scope
Package: curl (Red Hat JBoss Web Server 5) - Not affected
Package: httpd24-curl (Red Hat Software Collections) - Will not fix
Debian
CVE-2019-5482: curl - Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
vendor_debian·2019·CVSS 9.8
CVE-2019-5482 [CRITICAL] CVE-2019-5482: curl - Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
Scope: local
bookworm: resolved (fixed in 7.66.0-1)
bullseye: resolved (fixed in 7.66.0-1)
forky: resolved (fixed in 7.66.0-1)
sid: resolved (fixed in 7.66.0-1)
trixie: resolved (fixed in 7.66.0-1)
No detection rules found.
No public exploits indexed.
arXiv
BinSimDB: Benchmark Dataset Construction for Fine-Grained Binary Code Similarity Analysis
arxiv_fulltext·2024-10-14
BinSimDB: Benchmark Dataset Construction for Fine-Grained Binary Code Similarity Analysis
BinSimDB: Benchmark Dataset Construction for Fine-Grained Binary Code Similarity Analysis
BinSimDB: Benchmark Dataset Construction for Fine-Grained BCSA
Fei Zuo1( ) Cody Tompkins1
Qiang Zeng2 Lannan Luo2
Yung Ryn Choe3 Junghwan Rhee1
F. Zuo et al.
University of Central Oklahoma, Edmond, OK 73034, USA
\fzuo,ctompkins6,jrhee2\@uco.edu
George Mason University, Fairfax, VA 22030, USA
\zeng,lluo4\@gmu.edu
Sandia National Laboratories, Livermore, CA 94551, USA
[email protected]
## Abstract
Binary Code Similarity Analysis (BCSA) has a wide spectrum of applications, including plagiarism detection, vulnerability discovery, and malware analysis, thus drawing significant attention from the security community. However, conventional techniques often face challenges in balancing both accuracy
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
HackerOne
CVE-2019-5482: Heap buffer overflow in TFTP when using small blksize
hackerone·2020-11-14·CVSS 7.8
CVE-2019-5482 [HIGH] CVE-2019-5482: Heap buffer overflow in TFTP when using small blksize
CVE-2019-5482: Heap buffer overflow in TFTP when using small blksize
## Summary:
With a TFTP server that does not send OACK, but instead starts anyway with first block with 512 bytes block size, the curl library fails to assume default 512 bytes blocks. Instead it detects EOF and does not return an error code. Consequence is a truncated file that is 512 bytes without any error code.
My understanding is that from the RFC, a TFTP server might ignore blksize request and anyway send the default 512 bytes block size data.
Unless an OACK is received we should assume 512 block size, whether or not a particular blocksize was requested.
This was introduced by security fix of CVE-2019-5436:
257600341 tftp: use the current blksize for recvfrom()
## Potential Fix
We could revert 2576003415625d7b5
Bugzilla
CVE-2019-5482 mingw-curl: curl: heap buffer overflow in function tftp_receive_packet() [fedora-all]
bugzilla·2019-09-13·CVSS 9.8
CVE-2019-5482 [CRITICAL] CVE-2019-5482 mingw-curl: curl: heap buffer overflow in function tftp_receive_packet() [fedora-all]
CVE-2019-5482 mingw-curl: curl: heap buffer overflow in function tftp_receive_packet() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet() [fedora-all]
bugzilla·2019-09-13·CVSS 9.8
CVE-2019-5482 [CRITICAL] CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet() [fedora-all]
CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2019-5482 mingw-curl: curl: heap buffer overflow in function tftp_receive_packet() [epel-7]
bugzilla·2019-09-13·CVSS 9.8
CVE-2019-5482 [CRITICAL] CVE-2019-5482 mingw-curl: curl: heap buffer overflow in function tftp_receive_packet() [epel-7]
CVE-2019-5482 mingw-curl: curl: heap buffer overflow in function tftp_receive_packet() [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templat
Bugzilla
CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet()
bugzilla·2019-09-06·CVSS 7.8
CVE-2019-5482 [HIGH] CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet()
CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet()
A vulnerability was found in libcurl contains a heap buffer overflow in the function ('tftp_receive_packet()') that receives data from a TFTP server. It can call 'recvfrom()' with the default size for the buffer rather than with the size that was used to allocate it. Thus, the content that might overwrite the heap memory is controlled by the server.
Discussion:
Acknowledgments:
Name: the Curl project
Upstream: Thomas Vegas
---
What is the impact and cvss score for this issue?
https://access.redhat.com/security/cve/CVE-2019-5482 gives me 404.
---
Upstream patch: https://github.com/curl/curl/commit/facb0e4662415b5f28163e853dc6742ac5fafb3d
This flaw was introduced in January 2009 via https://github.com/curl/c
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.htmlhttps://curl.haxx.se/docs/CVE-2019-5482.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CI4QQ2RSZX4VCFM76SIWGKY6BY7UWIC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGDVKSLY5JUNJRLYRUA6CXGQ2LM63XC3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UA7KDM2WPM5CJDDGOEGFV6SSGD2J7RNT/https://seclists.org/bugtraq/2020/Feb/36https://security.gentoo.org/glsa/202003-29https://security.netapp.com/advisory/ntap-20191004-0003/https://security.netapp.com/advisory/ntap-20200416-0003/https://www.debian.org/security/2020/dsa-4633https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.htmlhttps://curl.haxx.se/docs/CVE-2019-5482.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CI4QQ2RSZX4VCFM76SIWGKY6BY7UWIC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGDVKSLY5JUNJRLYRUA6CXGQ2LM63XC3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UA7KDM2WPM5CJDDGOEGFV6SSGD2J7RNT/https://seclists.org/bugtraq/2020/Feb/36https://security.gentoo.org/glsa/202003-29https://security.netapp.com/advisory/ntap-20191004-0003/https://security.netapp.com/advisory/ntap-20200416-0003/https://www.debian.org/security/2020/dsa-4633https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2019-09-16
Published