CVE-2020-19909Integer Overflow or Wraparound in Curl

Severity
3.3LOWNVD
EPSS
0.0%
top 95.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22

Description

Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties report that this has no direct security impact on the curl user; however, it may (in theory) cause a denial of service to associated systems or networks if, for example, --retry-delay is misinterpreted as a value much smaller than what was intended. This is not especially plausible because the overflow only happens if the user was trying to specify that curl should wait weeks

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

Debianhaxx/curl< 7.66.0-1+3
Ubuntuhaxx/curl< 7.68.0-1ubuntu2.19
NVDhaxx/curl7.65.2

Patches

🔴Vulnerability Details

4
OSV
CVE-2020-19909: Integer overflow vulnerability in tool_operate2023-08-22
OSV
CVE-2020-19909: ** DISPUTED ** Integer overflow vulnerability in tool_operate2023-08-22
CVEList
CVE-2020-19909: Integer overflow vulnerability in tool_operate2023-08-22
GHSA
GHSA-2792-x8v5-77wp: Integer overflow vulnerability in tool_operate2023-08-22

📋Vendor Advisories

1
Debian
CVE-2020-19909: curl - Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large valu...2020
CVE-2020-19909 — Integer Overflow or Wraparound in Curl | cvebase