PT-2018-3797 · Ncurses+2 · Ncurses+2
Chung-Yi Lin
·
Published
2018-10-28
·
Updated
2022-06-14
·
CVE-2018-19211
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ncurses versions 6.1
Description
The issue is related to a NULL pointer dereference in the
nc parse entry function of the ncurses library, which can be exploited to cause a denial of service. This occurs even after the detection of a "dubious character `*' in name or alias field".Recommendations
For ncurses version 6.1, consider applying a patch or fix to resolve the NULL pointer dereference issue in the
nc parse entry function to prevent potential denial of service attacks.Exploit
Fix
DoS
NULL Pointer Dereference
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Ubuntu
Ncurses