Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10754

Опубликовано: 12 апр. 2018
Источник: redhat
CVSS3: 2.8

Описание

A NULL pointer dereference was found in the way the _nc_parse_entry function parses terminfo data for compilation. An attacker able to provide specially crafted terminfo data could use this flaw to crash the application parsing it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ncursesWill not fix
Red Hat Enterprise Linux 6ncursesWill not fix
Red Hat Enterprise Linux 7ncursesFix deferred
Red Hat Enterprise Linux 8ncursesNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1576119ncurses: NULL Pointer Dereference in _nc_parse_entry function in tinfo/parse_entry.c.

2.8 Low

CVSS3

Связанные уязвимости

ubuntu
почти 8 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

nvd
почти 8 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

suse-cvrf
около 6 лет назад

Security update for ncurses

2.8 Low

CVSS3