Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20397
HistoryMay 27, 2019 - 3:15 a.m.

Heap-based Buffer Overflow

2019-05-2703:15:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.07 Low

EPSS

Percentile

94.0%

libcurl.so is vulnerable to heap-based buffer overflow. The function tftp_receive_packet() that receives data from a TFTP server calls recvfrom() with the default size instead of the size that was allocated, potentially resulting in an overwrite of the heap memory.