CVE-2019-5443

HIGH

curl <=7.65.1 - Code Injection

Title source: llm

Description

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

Scores

CVSS v3 7.8
EPSS 0.0095
EPSS Percentile 76.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427 CWE-94
Status published

Affected Products (12)

haxx/curl < 7.65.1
oracle/enterprise_manager_ops_center
oracle/enterprise_manager_ops_center
oracle/http_server
oracle/http_server
oracle/mysql_server < 5.7.27
oracle/oss_support_tools
netapp/oncommand_insight
netapp/oncommand_unified_manager
netapp/oncommand_unified_manager
netapp/oncommand_workflow_automation
netapp/snapcenter

Timeline

Published Jul 02, 2019
Tracked Since Feb 18, 2026