First published: Wed May 22 2019(Updated: )
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/curl | 7.64.0-4+deb10u2 7.64.0-4+deb10u7 7.74.0-1.3+deb11u9 7.74.0-1.3+deb11u10 7.88.1-10+deb12u3 7.88.1-10+deb12u4 8.4.0-2 | |
debian/curl | <=7.52.1-5+deb9u9<=7.64.0-3<=7.52.1-5 | |
IBM Data Risk Manager | <=2.0.6 | |
libcurl | >=7.19.4<=7.64.1 | |
SUSE Linux | =15.0 | |
SUSE Linux | =15.1 | |
SUSE Linux | =42.3 | |
Red Hat Fedora | =29 | |
Debian Linux | =9.0 | |
Debian Linux | =10.0 | |
F5 Traffix Systems Signaling Delivery Controller | >=5.0.0<=5.1.0 | |
NetApp SolidFire & HCI Management Node | ||
NetApp SolidFire & HCI Storage Node | ||
NetApp SteelStore Cloud Integrated Storage | ||
Oracle Enterprise Manager Ops Center | =12.3.3 | |
Oracle Enterprise Manager Ops Center | =12.4.0 | |
MySQL | <=5.7.27 | |
MySQL | >=5.7.28<=8.0.17 | |
Oracle OSS Support Tools | =20.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5436 is a vulnerability in cURL libcurl that allows for a heap-based buffer overflow, leading to arbitrary code execution.
CVE-2019-5436 has a severity rating of 7.8, which is classified as high.
IBM Data Risk Manager version up to 2.0.6, curl packages in Debian, Haxx Libcurl, openSUSE Leap versions 15.0, 15.1, and 42.3, Fedoraproject Fedora version 29, and Debian Debian Linux versions 9.0 and 10.0 are affected by CVE-2019-5436.
To fix CVE-2019-5436 in IBM Data Risk Manager, you can apply the patch provided by IBM. Please visit the IBM support website for more information.
To fix CVE-2019-5436 in Debian, update the curl package to version 7.64.0-4+deb10u2, 7.64.0-4+deb10u7, 7.74.0-1.3+deb11u9, 7.74.0-1.3+deb11u10, 7.88.1-10+deb12u3, 7.88.1-10+deb12u4, or 8.4.0-2 depending on your version.