CVE-2020-19909 — Integer Overflow or Wraparound in Curl
Severity
3.3LOWNVD
EPSS
0.0%
top 95.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Description
Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties report that this has no direct security impact on the curl user; however, it may (in theory) cause a denial of service to associated systems or networks if, for example, --retry-delay is misinterpreted as a value much smaller than what was intended. This is not especially plausible because the overflow only happens if the user was trying to specify that curl should wait weeks …
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4
Patches
🔴Vulnerability Details
4📋Vendor Advisories
1Debian▶
CVE-2020-19909: curl - Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large valu...↗2020