Back

HIGH

curl: TFTP receive heap buffer overflow in tftp_receive_packet() function

Published May 28, 2019

Description

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Affected products

Remediation

Red Hat statement

This flaw exists if the user selects to use a "blksize" of 504 or smaller (default is 512). The smaller size that is used, the larger the possible overflow becomes. Users choosing a smaller size than default should be rare as the primary use case for changing the size is to make it larger. It is rare for users to use TFTP across the Internet. It is most commonly used within local networks.

References (19)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner hackerone
Published May 28, 2019
Updated Apr 15, 2026
Reserved Jan 4, 2019

CISA Vulnrichment

Updated Apr 15, 2026

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date May 22, 2019
Bugzilla 1710620

ENISA EUVD

Assigner hackerone
Published May 28, 2019
Updated Apr 15, 2026

GitHub

No data