Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Fedoraproject Subscribe
Cloud Backup Subscribe
Solidfire Baseboard Management Controller Subscribe
Solidfire Baseboard Management Controller Firmware Subscribe
Steelstore Subscribe
Opensuse Subscribe
Communications Operations Monitor Subscribe
Communications Session Border Controller Subscribe
Enterprise Manager Ops Center Subscribe
Mysql Server Subscribe
Oss Support Tools Subscribe
Enterprise Linux Subscribe
Jboss Core Services Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-4633-1 curl security update
EUVD EUVD EUVD-2019-15059 Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
Ubuntu USN Ubuntu USN USN-4129-1 curl vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 16 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-04-16T14:08:12.584Z

Reserved: 2019-01-04T00:00:00.000Z

Link: CVE-2019-5481

cve-icon Vulnrichment

Updated: 2024-08-04T19:54:53.498Z

cve-icon NVD

Status : Modified

Published: 2019-09-16T19:15:10.587

Modified: 2026-04-16T15:16:40.020

Link: CVE-2019-5481

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-09-11T00:00:00Z

Links: CVE-2019-5481 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses