CVE-2019-5443
HIGHcurl <= 7.65.1 - Uncontrolled Search Path Element via OpenSSL Engine Config
Title source: llmDescription
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
References (7)
Core 7
Core References
Mailing List, Patch, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2019/06/24/1
Broken Link vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/108881
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch, Vendor Advisory x_refsource_misc
https://curl.haxx.se/docs/CVE-2019-5443.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20191017-0002/
Scores
CVSS v3
7.8
EPSS
0.0099
EPSS Percentile
77.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-427
CWE-94
Status
published
Products (12)
haxx/curl
< 7.65.1
netapp/oncommand_insight
netapp/oncommand_unified_manager
7.3
netapp/oncommand_unified_manager
9.5
netapp/oncommand_workflow_automation
netapp/snapcenter
oracle/enterprise_manager_ops_center
12.3.3
oracle/enterprise_manager_ops_center
12.4.0
oracle/http_server
12.2.1.3.0
oracle/http_server
12.2.1.4.0
... and 2 more
Published
Jul 02, 2019
Tracked Since
Feb 18, 2026