CVE-2019-5481: Debian Linux
Critical severity, CVSS 9.8. EPSS: 7.5% chance of exploitation in the next 30 days.
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
- Haxx Curl: from 7.52.0, up to and including 7.65.3
- Netapp Cloud Backup: affected versions not specified
- Netapp Solidfire Baseboard Management Controller Firmware: affected versions not specified
- Netapp Steelstore: affected versions not specified
- Opensuse Leap: version 15.0 only; version 15.1 only
- Oracle Communications Operations Monitor: version 3.4 only; version 4.0 only; version 4.1 only; version 4.2 only; version 4.3 only
- Oracle Communications Session Border Controller: version 8.3 only; version 8.4 only
- Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
- Oracle MySQL Server: from 5.7.0, up to and including 5.7.28; from 8.0.0, up to and including 8.0.18
- Oracle OSS Support Tools: version 20.0 only
Published 2019-09-16. Last modified 2026-06-17.