cbcvebase.
CVE-2019-5482
published 2019-09-16

CVE-2019-5482: Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiancurl< curl 7.66.0-1 (bookworm)curl 7.66.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
haxxcurl
haxxcurl>= 0 < 7.66.0-17.66.0-1
haxxcurl>= 0 < 7.66.0-17.66.0-1
haxxcurl>= 0 < 7.66.0-17.66.0-1
haxxcurl>= 0 < 7.66.0-17.66.0-1
haxxcurl>= 0 < 7.47.0-1ubuntu2.147.47.0-1ubuntu2.14
haxxcurl>= 0 < 7.58.0-2ubuntu3.87.58.0-2ubuntu3.8
haxxcurl7.19.4 – 7.65.3
netapponcommand_unified_manager>= 7.3
netapponcommand_unified_manager>= 9.5
opensuseleap
opensuseleap
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclecommunications_session_border_controller
oraclecommunications_session_border_controller

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL