Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-5443

Опубликовано: 02 июл. 2019
Источник: ubuntu
Приоритет: medium
CVSS2: 4.4
CVSS3: 7.8

Описание

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

РелизСтатусПримечание
bionic

not-affected

cosmic

not-affected

devel

not-affected

disco

not-affected

esm-infra-legacy/trusty

not-affected

esm-infra/bionic

not-affected

esm-infra/xenial

not-affected

precise/esm

not-affected

trusty

ignored

end of standard support
trusty/esm

not-affected

Показывать по

Ссылки на источники

4.4 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
redhat
почти 6 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
nvd
почти 6 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
debian
почти 6 лет назад

A non-privileged user or program can put code and a config file in a k ...

CVSS3: 7.8
github
около 3 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
fstec
около 6 лет назад

Уязвимость библиотеки libcurl, связанная с неверным управлением генерацией кода, позволяющая нарушителю повысить свои привилегии или выполнить произвольный код

4.4 Medium

CVSS2

7.8 High

CVSS3