Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21492
HistorySep 12, 2019 - 7:10 a.m.

Arbitrary Code Execution

2019-09-1207:10:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24

0.098 Low

EPSS

Percentile

94.8%

libcurl.so is vulnerable to arbitrary code execution. A heap-based buffer overflow in the function tftp_receive_packet() that receives data from a TFTP server could potentially allow an attacker to execute arbitrary code by sending an OACK without the BLKSIZE option, when a BLKSIZE smaller than 512 bytes was requested by the TFTP client.

References