curl: TFTP receive heap buffer overflow in tftp_receive_packet() function
Published May 28, 2019
7.8
HIGHCVSS 3.1
EPSS 49.74%
Description
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
Affected products
-
Affected
- Fixed in 7.65.0
Configuration 3
- 29
Configuration 4
- 9.0
- 10.0
Configuration 5
- ≥ 5.0.0 · ≤ 5.1.0
Configuration 6
- n/a
- n/a
- n/a
Configuration 7
- 12.3.3
- 12.4.0
- ≤ 5.7.27
- ≥ 5.7.28 · ≤ 8.0.17
- 20.0
No data.
JBoss Core Services Apache HTTP Server 2.4.29 SP2
n/a
Fixed · RHSA-2019:1543
Red Hat Ansible Tower 3.5 for RHEL 7
ansible-tower-35/ansible-tower:3.5.6-1
Fixed · RHBA-2020:1539
Red Hat Ansible Tower 3.6 for RHEL 7
ansible-tower-36/ansible-tower:3.6.4-1
Fixed · RHBA-2020:1540
Red Hat Enterprise Linux 7
curl-0:7.29.0-57.el7
Fixed · RHSA-2020:1020
Red Hat Enterprise Linux 7.7 Extended Update Support
curl-0:7.29.0-54.el7_7.3
Fixed · RHSA-2020:2505
Red Hat Enterprise Linux 8
curl-0:7.61.1-12.el8
Fixed · RHSA-2020:1792
.NET Core 1.0 on Red Hat Enterprise Linux
rh-dotnetcore10-curl
Not affected
.NET Core 1.1 on Red Hat Enterprise Linux
rh-dotnetcore11-curl
Not affected
.NET Core 2.1 on Red Hat Enterprise Linux
rh-dotnet21-curl
Not affected
.NET Core 2.2 on Red Hat Enterprise Linux
rh-dotnet22-curl
Not affected
Red Hat Enterprise Linux 5
curl
Not affected
Red Hat Enterprise Linux 6
curl
Will not fix
Red Hat JBoss Core Services
jbcs-httpd24-curl
Affected
Red Hat JBoss Web Server 5
curl
Not affected
Red Hat Software Collections
httpd24-curl
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services Apache HTTP Server 2.4.29 SP2 | n/a | Fixed | RHSA-2019:1543 |
| Red Hat Ansible Tower 3.5 for RHEL 7 | ansible-tower-35/ansible-tower:3.5.6-1 | Fixed | RHBA-2020:1539 |
| Red Hat Ansible Tower 3.6 for RHEL 7 | ansible-tower-36/ansible-tower:3.6.4-1 | Fixed | RHBA-2020:1540 |
| Red Hat Enterprise Linux 7 | curl-0:7.29.0-57.el7 | Fixed | RHSA-2020:1020 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | curl-0:7.29.0-54.el7_7.3 | Fixed | RHSA-2020:2505 |
| Red Hat Enterprise Linux 8 | curl-0:7.61.1-12.el8 | Fixed | RHSA-2020:1792 |
| .NET Core 1.0 on Red Hat Enterprise Linux | rh-dotnetcore10-curl | Not affected | n/a |
| .NET Core 1.1 on Red Hat Enterprise Linux | rh-dotnetcore11-curl | Not affected | n/a |
| .NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21-curl | Not affected | n/a |
| .NET Core 2.2 on Red Hat Enterprise Linux | rh-dotnet22-curl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | curl | Will not fix | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-curl | Affected | n/a |
| Red Hat JBoss Web Server 5 | curl | Not affected | n/a |
| Red Hat Software Collections | httpd24-curl | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw exists if the user selects to use a "blksize" of 504 or smaller (default is 512). The smaller size that is used, the larger the possible overflow becomes. Users choosing a smaller size than default should be rare as the primary use case for changing the size is to make it larger. It is rare for users to use TFTP across the Internet. It is most commonly used within local networks.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00008.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00017.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/09/11/6 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-5436 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1710620 Issue Tracking
- https://curl.haxx.se/docs/CVE-2019-5436.html x_refsource_CONFIRMExploitPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15026 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SMG3V4VTX2SE3EW3HQTN3DDLQBTORQC2/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-5436
- https://seclists.org/bugtraq/2020/Feb/36 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202003-29 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190606-0004/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K55133295 x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K55133295?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2019-5436
- https://www.debian.org/security/2020/dsa-4633 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISC
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data