A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
2019-05-28T19:29:06.127
2024-11-21T04:44:55.937
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | haxx | libcurl | ≤ 7.64.1 | Yes |
| Operating System | opensuse | leap | 15.0 | Yes |
| Operating System | opensuse | leap | 15.1 | Yes |
| Operating System | opensuse | leap | 42.3 | Yes |
| Operating System | fedoraproject | fedora | 29 | Yes |
| Operating System | debian | debian_linux | 9.0 | Yes |
| Operating System | debian | debian_linux | 10.0 | Yes |
| Application | f5 | traffix_signaling_delivery_controller | ≤ 5.1.0 | Yes |
| Application | netapp | hci_management_node | - | Yes |
| Application | netapp | solidfire | - | Yes |
| Application | netapp | steelstore_cloud_integrated_storage | - | Yes |
| Application | oracle | enterprise_manager_ops_center | 12.3.3 | Yes |
| Application | oracle | enterprise_manager_ops_center | 12.4.0 | Yes |
| Application | oracle | mysql_server | ≤ 5.7.27 | Yes |
| Application | oracle | mysql_server | ≤ 8.0.17 | Yes |
| Application | oracle | oss_support_tools | 20.0 | Yes |