Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-39537

Опубликовано: 04 авг. 2020
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

A heap overflow vulnerability has been found in the ncurses package, particularly in the "tic". This flaw results from a lack of proper bounds checking during input processing. By exploiting this boundary error, an attacker can create a malicious file, deceive the victim into opening it using the affected software, and initiate an out-of-bounds write, potentially impacting system availability.

Отчет

Red Hat Product Security has rated this issue as having a Low security impact because processing terminfo descriptions in the source form should be handled the same way as executable files or source code of any programming language. Users are not supposed to use untrusted terminfo descriptions.

Меры по смягчению последствий

Do not compile untrusted terminfo descriptions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ncursesOut of support scope
Red Hat Enterprise Linux 7ncursesOut of support scope
Red Hat Enterprise Linux 8ncursesFix deferred
Red Hat Enterprise Linux 9ncursesNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2006978ncurses: heap-based buffer overflow in _nc_captoinfo() in captoinfo.c

EPSS

Процентиль: 58%
0.00365
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

CVSS3: 8.8
nvd
больше 4 лет назад

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

CVSS3: 8.8
msrc
больше 4 лет назад

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

CVSS3: 8.8
debian
больше 4 лет назад

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in ca ...

suse-cvrf
больше 4 лет назад

Security update for ncurses

EPSS

Процентиль: 58%
0.00365
Низкий

5.5 Medium

CVSS3