CVE-2019-5481

CRITICAL

Haxx Curl < 7.65.3 - Double Free

Title source: rule

Description

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

Scores

CVSS v3 9.8
EPSS 0.0469
EPSS Percentile 89.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status published

Affected Products (22)

haxx/curl < 7.65.3
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
netapp/cloud_backup
netapp/steelstore
netapp/solidfire_baseboard_management_controller_firmware
oracle/communications_operations_monitor
oracle/communications_operations_monitor
oracle/communications_operations_monitor
oracle/communications_operations_monitor
oracle/communications_operations_monitor
oracle/communications_session_border_controller
oracle/communications_session_border_controller
oracle/enterprise_manager_ops_center
... and 7 more

Timeline

Published Sep 16, 2019
Tracked Since Feb 18, 2026