Back

CRITICAL

curl: heap buffer overflow in function tftp_receive_packet()

Published Sep 16, 2019

Description

Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

Affected products

Remediation

Red Hat mitigation

Do not use TFTP with curl with smaller than the default BLKSIZE.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Sep 16, 2019
Updated Apr 15, 2026
Reserved Jan 4, 2019
CISA Vulnrichment
Updated Apr 15, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 11, 2019