HIGH · 7.8

CVE-2019-5443

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") o...

Vulnerability Description

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HaxxCurl<= 7.65.1
MicrosoftWindows-
OracleEnterprise Manager Ops Center12.3.3
OracleHttp Server12.2.1.3.0
OracleMysql Server>= 5.0.0, <= 5.7.27
OracleOss Support Tools20.0
NetappOncommand Insight-
NetappOncommand Unified Manager>= 7.3
NetappOncommand Workflow Automation-
NetappSnapcenter-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-5443?

CVE-2019-5443 is a vulnerability with a CVSS score of 7.8 (HIGH). A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") o...

How severe is CVE-2019-5443?

CVE-2019-5443 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-5443?

Check the references section above for vendor advisories and patch information. Affected products include: Haxx Curl, Microsoft Windows, Oracle Enterprise Manager Ops Center, Oracle Http Server, Oracle Mysql Server.