Описание
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип | 
|---|---|---|---|---|
| curl | fixed | 7.64.0-4 | package | |
| curl | fixed | 7.52.1-5+deb9u10 | stretch | package | 
Примечания
https://curl.haxx.se/docs/CVE-2019-5436.html
Introduced by: https://github.com/curl/curl/commit/0516ce7786e95
Fixed by: https://github.com/curl/curl/commit/2576003415625d7b5f0e390902f8097830b82275
EPSS
Процентиль: 86%
0.03089
Низкий
Связанные уязвимости
CVSS3: 7.8
ubuntu
больше 6 лет назад
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
CVSS3: 7
redhat
больше 6 лет назад
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
CVSS3: 7.8
nvd
больше 6 лет назад
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
EPSS
Процентиль: 86%
0.03089
Низкий