TFTP: cURL and libcurl TFTP blksize Heap Buffer Overflow

This signature detects attempts to exploit a known vulnerability against cURL and libcurl. A successful attack can lead to arbitrary code execution.

Extended Description

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Affected Products

Oracle mysql_server

References

CVE: CVE-2019-5482

Short Name
TFTP:CURL-LIBCURL-OF
Severity
Minor
Recommended
False
Recommended Action
None
Category
TFTP
Keywords
Buffer CVE-2019-5436 CVE-2019-5482 Heap Overflow TFTP and blksize cURL libcurl
Release Date
01/16/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Rarely
Vendors

F5

Fedoraproject

Opensuse

Oracle

Netapp

Debian

Haxx

CVSS Score

7.5

4.6

Found a potential security threat?