PT-2018-3797 · Ncurses+2 · Ncurses+2

Chung-Yi Lin

·

Publicado

2018-10-28

·

Atualizado

2022-06-14

·

CVE-2018-19211

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ncurses versions 6.1
Description The issue is related to a NULL pointer dereference in the nc parse entry function of the ncurses library, which can be exploited to cause a denial of service. This occurs even after the detection of a "dubious character `*' in name or alias field".
Recommendations For ncurses version 6.1, consider applying a patch or fix to resolve the NULL pointer dereference issue in the nc parse entry function to prevent potential denial of service attacks.

Exploit

Correção

DoS

NULL Pointer Dereference

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-03954
CVE-2018-19211
OPENSUSE-SU-2018_4034-1
OPENSUSE-SU-2018_4055-1
SUSE-SU-2018:3967-1
SUSE-SU-2018:4000-1
SUSE-SU-2018_3967-1
SUSE-SU-2018_4000-1
USN-5477-1

Produtos afetados

Suse
Ubuntu
Ncurses