CVE-2019-5436

medium
Published 2020-04-28 Β· Modified 2020-04-28
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description curl: TFTP receive heap buffer overflow in tftp_receive_packet() function Red Hat statement This flaw exists if the user selects to use a "blksize" of 504 or smaller (default is 512). The smaller size that is used, the larger the possible overflow becomes. Users choosing a smaller size than default should be rare as the primary use case for changing the size is to make it larger. It…

Description

curl: TFTP receive heap buffer overflow in tftp_receive_packet() function

Red Hat statement

This flaw exists if the user selects to use a "blksize" of 504 or smaller (default is 512). The smaller size that is used, the larger the possible overflow becomes. Users choosing a smaller size than default should be rare as the primary use case for changing the size is to make it larger. It is rare for users to use TFTP across the Internet. It is most commonly used within local networks.

CVSS v3: 7.0 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
JBoss Core Services Apache HTTP Server 2.4.29 SP2RHSA-2019:15432019-06-18T00:00:00Z
Red Hat Ansible Tower 3.5 for RHEL 7ansible-tower-35/ansible-tower:3.5.6-1RHBA-2020:15392020-04-22T00:00:00Z
Red Hat Ansible Tower 3.6 for RHEL 7ansible-tower-36/ansible-tower:3.6.4-1RHBA-2020:15402020-04-22T00:00:00Z
Red Hat Enterprise Linux 7curl-0:7.29.0-57.el7RHSA-2020:10202020-03-31T00:00:00Z
Red Hat Enterprise Linux 7.7 Extended Update Supportcurl-0:7.29.0-54.el7_7.3RHSA-2020:25052020-06-12T00:00:00Z
Red Hat Enterprise Linux 8curl-0:7.61.1-12.el8RHSA-2020:17922020-04-28T00:00:00Z

Package state

ProductPackageState
.NET Core 1.0 on Red Hat Enterprise Linuxrh-dotnetcore10-curlNot affected
.NET Core 1.1 on Red Hat Enterprise Linuxrh-dotnetcore11-curlNot affected
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21-curlNot affected
.NET Core 2.2 on Red Hat Enterprise Linuxrh-dotnet22-curlNot affected
Red Hat Enterprise Linux 5curlNot affected
Red Hat Enterprise Linux 6curlWill not fix
Red Hat JBoss Core Servicesjbcs-httpd24-curlAffected
Red Hat JBoss Web Server 5curlNot affected
Red Hat Software Collectionshttpd24-curlFix deferred

Apply commands

bash fix
Apply RHBA-2020:1539 for Red Hat Ansible Tower 3.5 for RHEL 7
yum update -y ansible-tower
# or:
dnf upgrade -y ansible-tower

Affected

VendorProductVersion
redhat.NET Core 1.0 on Red Hat Enterprise LinuxNot affected
redhat.NET Core 1.1 on Red Hat Enterprise LinuxNot affected
redhat.NET Core 2.1 on Red Hat Enterprise LinuxNot affected
redhat.NET Core 2.2 on Red Hat Enterprise LinuxNot affected
redhatRed Hat Enterprise Linux 5Not affected
redhatRed Hat JBoss Core ServicesAffected
redhatRed Hat JBoss Web Server 5Not affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
arch Arch Fixed 1 release
VersionStatusFixed in
β€” Fixed 7.65.0-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 7.64.0-4
sid Fixed 7.64.0-4
forky Fixed 7.64.0-4
bullseye Fixed 7.64.0-4
bookworm Fixed 7.64.0-4
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.