Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-5436

Опубликовано: 22 мая 2019
Источник: redhat
CVSS3: 7
EPSS Средний

Описание

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Отчет

This flaw exists if the user selects to use a "blksize" of 504 or smaller (default is 512). The smaller size that is used, the larger the possible overflow becomes. Users choosing a smaller size than default should be rare as the primary use case for changing the size is to make it larger. It is rare for users to use TFTP across the Internet. It is most commonly used within local networks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 1.0 on Red Hat Enterprise Linuxrh-dotnetcore10-curlNot affected
.NET Core 1.1 on Red Hat Enterprise Linuxrh-dotnetcore11-curlNot affected
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21-curlNot affected
.NET Core 2.2 on Red Hat Enterprise Linuxrh-dotnet22-curlNot affected
Red Hat Enterprise Linux 5curlNot affected
Red Hat Enterprise Linux 6curlWill not fix
Red Hat JBoss Core ServicescurlAffected
Red Hat JBoss Web Server 5curlNot affected
Red Hat Software Collectionshttpd24-curlFix deferred
JBoss Core Services Apache HTTP Server 2.4.29 SP2FixedRHSA-2019:154318.06.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1710620curl: TFTP receive heap buffer overflow in tftp_receive_packet() function

EPSS

Процентиль: 96%
0.29542
Средний

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
nvd
около 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
debian
около 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or ar ...

suse-cvrf
около 6 лет назад

Security update for curl

suse-cvrf
около 6 лет назад

Security update for curl

EPSS

Процентиль: 96%
0.29542
Средний

7 High

CVSS3