Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19217

Опубликовано: 12 нояб. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

Отчет

This vulnerability is rated as moderate because it allows a remote attacker to cause a denial of service via a NULL pointer dereference, exploiting this flaw would crash the application, impacting availability but not compromising system integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ncursesWill not fix
Red Hat Enterprise Linux 6ncursesWill not fix
Red Hat Enterprise Linux 7ncursesWill not fix
Red Hat Enterprise Linux 8ncursesWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1652606ncurses: Null pointer dereference at function _nc_name_match

EPSS

Процентиль: 60%
0.00404
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

CVSS3: 6.5
nvd
около 7 лет назад

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

CVSS3: 6.5
debian
около 7 лет назад

In ncurses, possibly a 6.x version, there is a NULL pointer dereferenc ...

CVSS3: 6.5
github
больше 3 лет назад

** DISPUTED ** In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party.

EPSS

Процентиль: 60%
0.00404
Низкий

6.5 Medium

CVSS3