curl / Docs / Vulnerability table / 7.64.0 vulnerabilities

Vulnerabilities in curl 7.64.0

curl version 7.64.0 was released on February 6 2019. The following 5 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
FTP-KRB double-free7.52.07.65.3CVE-2019-5481CWE-415: Double Free
TFTP small blocksize heap buffer overflow7.19.47.65.3CVE-2019-5482CWE-122: Heap-based Buffer Overflow
Windows OpenSSL engine code injection7.61.07.65.1CVE-2019-5443CWE-94: Code Injection
TFTP receive buffer overflow7.19.47.64.1CVE-2019-5436CWE-122: Heap-based Buffer Overflow
Integer overflows in curl_url_set7.62.07.64.1CVE-2019-5435CWE-131: Incorrect Calculation of Buffer Size

Changelog for curl 7.64.0

See vulnerability summary for the previous release: 7.63.0 or the subsequent release: 7.64.1