PT-2019-5180 · Ncurses+8 · Ncurses+8

Publicado

2019-10-13

·

Atualizado

2023-05-23

·

CVE-2019-17594

CVSS v3.1

5.3

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ncurses versions prior to 6.1-20191012
Description The issue is related to a heap-based buffer over-read in the nc find entry function, located in the tinfo/comp hash.c file of the terminfo library in ncurses. This could potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 6.1-20191012, update to version 6.1-20191012 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable nc find entry function until a patch is available.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2021:4426
ALT-PU-2020-3296
BDU:2020-01853
CESA-2021_4426
CVE-2019-17594
MGASA-2019-0387
OPENSUSE-SU-2019:2550-1
OPENSUSE-SU-2019:2551-1
OPENSUSE-SU-2019_2550-1
OPENSUSE-SU-2019_2551-1
RHSA-2021:4426
RHSA-2021_4426
RLSA-2021:4426
SUSE-SU-2019:2997-1
SUSE-SU-2019:3094-1
SUSE-SU-2019_2997-1
USN-5477-1
USN-6099-1

Produtos afetados

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Ncurses