Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19217

Опубликовано: 12 нояб. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

A vulnerability was found in GNU ncurses, where a NULL pointer dereference in the _nc_name_match function can lead to a denial of service, a remote attacker could exploit this vulnerability to crash the application.

Отчет

This vulnerability is rated as moderate because it allows a remote attacker to cause a denial of service via a NULL pointer dereference, exploiting this flaw would crash the application, impacting availability but not compromising system integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ncursesWill not fix
Red Hat Enterprise Linux 6ncursesWill not fix
Red Hat Enterprise Linux 7ncursesWill not fix
Red Hat Enterprise Linux 8ncursesNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1652606ncurses: Null pointer dereference at function _nc_name_match

EPSS

Процентиль: 68%
0.01298
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

CVSS3: 6.5
nvd
почти 8 лет назад

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

msrc
12 месяцев назад

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

CVSS3: 6.5
debian
почти 8 лет назад

In ncurses, possibly a 6.x version, there is a NULL pointer dereferenc ...

CVSS3: 6.5
github
больше 4 лет назад

** DISPUTED ** In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party.

EPSS

Процентиль: 68%
0.01298
Низкий

6.5 Medium

CVSS3