Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16879

Опубликовано: 22 нояб. 2017
Источник: debian

Описание

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ncursesfixed6.0+20171125-1package
ncursesfixed6.0+20161126-1+deb9u2stretchpackage
ncursesfixed5.9+20140913-1+deb8u3jessiepackage
ncursesignoredwheezypackage

Примечания

  • PoC https://packetstormsecurity.com/files/download/145045/tic-overflow.tgz

  • http://invisible-island.net/ncurses/NEWS.html#t20171125

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.

CVSS3: 2.5
redhat
около 8 лет назад

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.

CVSS3: 7.8
nvd
около 8 лет назад

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.

CVSS3: 7.8
github
больше 3 лет назад

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.

suse-cvrf
около 8 лет назад

Security update for ncurses