First published: Wed May 22 2019(Updated: )
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data Risk Manager | <=2.0.6 | |
debian/curl | 7.64.0-4+deb10u2 7.64.0-4+deb10u7 7.74.0-1.3+deb11u9 7.74.0-1.3+deb11u10 7.88.1-10+deb12u3 7.88.1-10+deb12u4 8.4.0-2 | |
debian/curl | <=7.52.1-5+deb9u9<=7.64.0-3<=7.52.1-5 | |
Haxx Libcurl | >=7.19.4<=7.64.1 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =42.3 | |
Fedoraproject Fedora | =29 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
F5 Traffix Signaling Delivery Controller | >=5.0.0<=5.1.0 | |
Netapp Hci Management Node | ||
Netapp Solidfire | ||
Netapp Steelstore Cloud Integrated Storage | ||
Oracle Enterprise Manager Ops Center | =12.3.3 | |
Oracle Enterprise Manager Ops Center | =12.4.0 | |
Oracle Mysql Server | <=5.7.27 | |
Oracle Mysql Server | >=5.7.28<=8.0.17 | |
Oracle OSS Support Tools | =20.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5436 is a vulnerability in cURL libcurl that allows for a heap-based buffer overflow, leading to arbitrary code execution.
CVE-2019-5436 has a severity rating of 7.8, which is classified as high.
IBM Data Risk Manager version up to 2.0.6, curl packages in Debian, Haxx Libcurl, openSUSE Leap versions 15.0, 15.1, and 42.3, Fedoraproject Fedora version 29, and Debian Debian Linux versions 9.0 and 10.0 are affected by CVE-2019-5436.
To fix CVE-2019-5436 in IBM Data Risk Manager, you can apply the patch provided by IBM. Please visit the IBM support website for more information.
To fix CVE-2019-5436 in Debian, update the curl package to version 7.64.0-4+deb10u2, 7.64.0-4+deb10u7, 7.74.0-1.3+deb11u9, 7.74.0-1.3+deb11u10, 7.88.1-10+deb12u3, 7.88.1-10+deb12u4, or 8.4.0-2 depending on your version.