← Back

CVE-2019-5443

nvd nist
Published: Jul 2, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

Affected (13)

1 product
Curl
4 products
Enterprise Manager Ops Center
Http Server
Mysql Server
Oss Support Tools
4 products
Oncommand Insight
Oncommand Unified Manager
Oncommand Workflow Automation
Snapcenter
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 7.65.1
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.3.3
Version 12.4.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
From 5.0.0 to 5.7.27
From 8.0.0 to 8.0.17
Version 20.0
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Netapp
From 9.5
From 7.3
All versions
All versions

References (14)

Source: support@hackerone.com
Mailing ListPatchThird Party Advisory
Source: support@hackerone.com
Broken Link
Source: support@hackerone.com
PatchVendor Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.