CVE-2019-5443: Code Injection
Published Jul 2, 2019
·Updated
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
Affected Software
14 affected components
haxx curl<=7.65.1
Microsoft Windows
Oracle Enterprise Manager Ops Center=12.3.3
Oracle Enterprise Manager Ops Center=12.4.0
Oracle HTTP Server=12.2.1.3.0
Oracle HTTP Server=12.2.1.4.0
Oracle MySQL Server>=5.0.0<=5.7.27
Oracle MySQL Server>=8.0.0<=8.0.17
Oracle OSS Support Tools=20.0
NetApp OnCommand Insight
NetApp Oncommand Unified Manager Windows>=7.3
NetApp Oncommand Unified Manager Vmware Vsphere>=9.5
NetApp OnCommand Workflow Automation
NetApp Snapcenter
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 2, 2019
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-5443?
CVE-2019-5443 is a vulnerability in the Curl software that allows a non-privileged user or program to execute code on invocation.
2
How severe is CVE-2019-5443?
CVE-2019-5443 has a severity rating of 7.8 (high).
3
Which software versions are affected by CVE-2019-5443?
Curl version 7.65.1 and earlier versions are affected by CVE-2019-5443.
4
How can I fix CVE-2019-5443?
Upgrade to a version of Curl that is not affected by the vulnerability, such as version 7.65.2 or later.
5
Where can I find more information about CVE-2019-5443?
You can find more information about CVE-2019-5443 on the official Curl website or security advisories.