Back
CVE-2019-5481
CRITICAL
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
Published: Sep 16, 2019
Modified: Jun 17, 2026
CWE-415
CWE-415
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (23)
| Vendor | Product | Version |
|---|---|---|
| haxx | curl | * ≥ 7.52.0 |
| fedoraproject | fedora | 29 |
| fedoraproject | fedora | 30 |
| fedoraproject | fedora | 31 |
| netapp | cloud_backup | - |
| netapp | steelstore | - |
| netapp | solidfire_baseboard_management_controller_firmware | - |
| oracle | communications_operations_monitor | 3.4 |
| oracle | communications_operations_monitor | 4.0 |
| oracle | communications_operations_monitor | 4.1 |
| oracle | communications_operations_monitor | 4.2 |
| oracle | communications_operations_monitor | 4.3 |
| oracle | communications_session_border_controller | 8.3 |
| oracle | communications_session_border_controller | 8.4 |
| oracle | enterprise_manager_ops_center | 12.3.3 |
| oracle | enterprise_manager_ops_center | 12.4.0 |
| oracle | mysql_server | * ≥ 5.7.0 |
| oracle | mysql_server | * ≥ 8.0.0 |
| oracle | oss_support_tools | 20.0 |
| debian | debian_linux | 9.0 |
…and 3 more
GitHub Security Advisory GHSA-hr98-frg6-wvvr
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
References (26)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.html Mailing List, Third Party Advisory
- https://curl.haxx.se/docs/CVE-2019-5481.html Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6CI4QQ2RSZX4VCFM76SIWGKY6BY7UWIC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGDVKSLY5JUNJRLYRUA6CXGQ2LM63XC3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UA7KDM2WPM5CJDDGOEGFV6SSGD2J7RNT/
- https://seclists.org/bugtraq/2020/Feb/36 Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202003-29 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20191004-0003/ Third Party Advisory
- https://www.debian.org/security/2020/dsa-4633 Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00048.html Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00055.html Mailing List, Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
7.27%
Top 6% most likely to be exploited
Threat Score
41.4 / 100
Data Sources
NVD
EPSS
GitHub