CVE-2019-5482: Debian Linux

Critical severity, CVSS 9.8. EPSS: 17.9% chance of exploitation in the next 30 days.

Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
  • Haxx Curl: from 7.19.4, up to and including 7.65.3
  • Netapp Cloud Backup: affected versions not specified
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Unified Manager: from 7.3; from 9.5
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Communications Operations Monitor: version 3.4 only; version 4.0 only; version 4.1 only; version 4.2 only; version 4.3 only
  • Oracle Communications Session Border Controller: version 8.3 only; version 8.4 only
  • Oracle Enterprise Manager Ops Center: version 12.3.3 only; version 12.4.0 only
  • Oracle HTTP Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Hyperion Essbase: version 11.1.2.4 only
  • Oracle MySQL Server: from 5.0.0, up to and including 5.7.28; from 8.0.0, up to and including 8.0.18
  • Oracle OSS Support Tools: version 20.0 only

Published 2019-09-16. Last modified 2026-06-17.