CVE-2019-5436: Debian Linux

High severity, CVSS 7.8. EPSS: 49.7% chance of exploitation in the next 30 days.

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • F5 Traffix Signaling Delivery Controller: from 5.0.0, up to and including 5.1.0
  • Fedoraproject Fedora: version 29 only
  • Haxx Libcurl: from 7.19.4, up to and including 7.64.1
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 15.1 only; version 42.3 only
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
  • Oracle MySQL Server: up to and including 5.7.27; from 5.7.28, up to and including 8.0.17
  • Oracle OSS Support Tools: version 20.0 only

Published 2019-05-28. Last modified 2026-06-17.