Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5443


A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.


Published

2019-07-02T19:15:10.790

Last Modified

2024-11-21T04:44:56.657

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-94
  • Type: Primary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application haxx curl ≤ 7.65.1 Yes
Operating System microsoft windows - No
Application oracle enterprise_manager_ops_center 12.3.3 Yes
Application oracle enterprise_manager_ops_center 12.4.0 Yes
Application oracle http_server 12.2.1.3.0 Yes
Application oracle http_server 12.2.1.4.0 Yes
Application oracle mysql_server ≤ 5.7.27 Yes
Application oracle mysql_server ≤ 8.0.17 Yes
Application oracle oss_support_tools 20.0 Yes
Application netapp oncommand_insight - Yes
Application netapp oncommand_unified_manager ≥ 7.3 Yes
Application netapp oncommand_unified_manager ≥ 9.5 Yes
Application netapp oncommand_workflow_automation - Yes
Application netapp snapcenter - Yes

References