ZeroHour

CVE-2019-5436

PoC
CVSS 3.1
7.8 high
EPSS
50%p99
Published
()
Modified
Description

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Vendors
haxxopensusefedoraprojectdebianf5netapporacle
Products
libcurl, leap, fedora, debian linux, traffix signaling delivery controller, hci management node, solidfire, steelstore cloud integrated storage, enterprise manager ops center, mysql server, oss support tools
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.