CVE-2019-5436

HIGHCVSS 7.8/10EPSS 49.74%

Last modified

CVE-2019-5436 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.. EPSS estimates a 49.74% chance of exploitation in the next 30 days.

Description

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
49.74%

98.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HaxxLibcurl>= 7.19.4, <= 7.64.1
OpensuseLeap15.0
OpensuseLeap15.1
OpensuseLeap42.3
FedoraprojectFedora29
DebianDebian Linux9.0
DebianDebian Linux10.0
F5Traffix Signaling Delivery Controller>= 5.0.0, <= 5.1.0
NetappHci Management NodeAll versions
NetappSolidfireAll versions
NetappSteelstore Cloud Integrated StorageAll versions
OracleEnterprise Manager Ops Center12.3.3
OracleEnterprise Manager Ops Center12.4.0
OracleMysql Server<= 5.7.27
OracleMysql Server>= 5.7.28, <= 8.0.17
OracleOss Support Tools20.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-5436?
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
How severe is CVE-2019-5436?
CVE-2019-5436 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 49.74% probability of exploitation in the next 30 days.
How do I fix CVE-2019-5436?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-5436?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST