Integer overflow in cURL - CVE-2019-5435
Published: May 23, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in curl_url_set() function on 32-bit systems. A remote attacker can pass an overly long URL to the affected application, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Amazon Linux AMI
Arch Linux
Gentoo Linux
Slackware Linux
Fedora
curl (Ubuntu package)
curl (Alpine package)
curl
How to mitigate CVE-2019-5435
curl (Ubuntu package) - addressed in versions 7.47.0-1ubuntu2.13, 7.58.0-2ubuntu3.7, 7.61.0-1ubuntu2.4, 7.64.0-2ubuntu1.1
curl (Alpine package) - update to 7.64.0-r2
curl - addressed in versions 7.61.1-11.fc29, 7.64.0-7.fc30
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Ubuntu update for curl
- Slackware Linux update for curl
- Arch Linux update for lib32-curl
- Arch Linux update for lib32-libcurl-compat
- Arch Linux update for lib32-libcurl-gnutls
- Amazon Linux AMI update for curl
- Gentoo update for cURL
- Integer overflow in curl (Alpine package)
- Multiple vulnerabilities in Dell Data Protection Central
- Fedora 29 update for curl
- Fedora 30 update for curl