Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19211

Опубликовано: 28 окт. 2018
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

A vulnerability was found in GNU ncurses due to a NULL pointer dereference in the _nc_parse_entry function within parse_entry.c, where an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to a crash and causing a denial of service condition.

Отчет

This vulnerability was rated as LOW severity because it requires the victim to open a specially crafted file. While it doesn’t allow full system compromise, it can cause the application to crash temporarily.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ncursesWill not fix
Red Hat Enterprise Linux 6ncursesWill not fix
Red Hat Enterprise Linux 7ncursesWill not fix
Red Hat Enterprise Linux 8ncursesWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1652600ncurses: Null pointer dereference at function _nc_parse_entry in parse_entry.c

EPSS

Процентиль: 69%
0.0135
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

CVSS3: 5.5
nvd
почти 8 лет назад

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

CVSS3: 5.5
debian
почти 8 лет назад

In ncurses 6.1, there is a NULL pointer dereference at function _nc_pa ...

suse-cvrf
больше 7 лет назад

Security update for ncurses

suse-cvrf
больше 7 лет назад

Security update for ncurses

EPSS

Процентиль: 69%
0.0135
Низкий

4.7 Medium

CVSS3