PT-2017-11436 · Gnu+2 · Ncurses+2

Published

2017-06-29

·

Updated

2022-05-26

·

CVE-2017-10684

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ncurses version 6.0
Description The issue is related to a stack-based buffer overflow in the fmt entry function. This can be exploited with a crafted input, potentially leading to a remote arbitrary code execution attack.
Recommendations For ncurses version 6.0, update to a version that fixes the buffer overflow issue in the fmt entry function to prevent remote arbitrary code execution attacks.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10684
MGASA-2018-0001
MGASA-2018-0002
OPENSUSE-SU-2017_1882-1
SUSE-SU-2017:1790-1
SUSE-SU-2017:1815-1
SUSE-SU-2017:2075-1
SUSE-SU-2017:2076-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017_1790-1
SUSE-SU-2017_1815-1
SUSE-SU-2017_2075-1
SUSE-SU-2017_2076-1
USN-5448-1

Affected Products

Suse
Ubuntu
Ncurses