Related Vulnerabilities: CVE-2019-5435  

libcurl before 7.65.0 contains two integer overflows in the curl_url_set() function that if triggered, can lead to a too small buffer allocation and a subsequent heap buffer overflow. The flaws only exist on 32 bit architectures and require excessive string input lengths.

Severity High

Remote Yes

Type Arbitrary code execution

Description

libcurl before 7.65.0 contains two integer overflows in the curl_url_set() function that if triggered, can lead to a too small buffer allocation and a subsequent heap buffer overflow. The flaws only exist on 32 bit architectures and require excessive string input lengths.

AVG-963 lib32-curl 7.64.1-1 7.65.0-1 High Testing

AVG-962 lib32-libcurl-compat 7.64.1-1 7.65.0-1 High Testing

AVG-961 lib32-libcurl-gnutls 7.64.1-1 7.65.0-1 High Testing

https://curl.haxx.se/docs/CVE-2019-5435.html
https://github.com/curl/curl/commit/5fc28510a4664f4