Lucene search

K
ibmIBM0C300C196833A53579F63C1FFC55C9F60E845E6B276A4574DEAED711129AD3CB
HistoryJun 24, 2020 - 6:53 p.m.

Security Bulletin: IBM Bootable Media Creator (BoMC) is affected by a vulnerability in cURL (CVE-2019-5482)

2020-06-2418:53:55
www.ibm.com
16

0.098 Low

EPSS

Percentile

94.8%

Summary

IBM Bootable Media Creator (BoMC) has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2019-5482
**DESCRIPTION:**cURL libcurl is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the tftp_receive_packet function. By sending specially-crafted request containing an OACK without the BLKSIZE option, a remote attacker could overflow a buffer and execute arbitrary code on the system.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/166942 for the current score.
CVSS Vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

The fix is downloaded automatically by BoMC in the background and is not independently accessible on Fix Central.

Remediation/Fixes

The fix is downloaded automatically by BoMC in the background and is not independently accessible on Fix Central.

Workarounds and Mitigations

None