PT-2019-5180 · Ncurses+8 · Ncurses+8

Published

2019-10-13

·

Updated

2023-05-23

·

CVE-2019-17594

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ncurses versions prior to 6.1-20191012
Description The issue is related to a heap-based buffer over-read in the nc find entry function, located in the tinfo/comp hash.c file of the terminfo library in ncurses. This could potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 6.1-20191012, update to version 6.1-20191012 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable nc find entry function until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4426
ALT-PU-2020-3296
BDU:2020-01853
CESA-2021_4426
CVE-2019-17594
MGASA-2019-0387
OPENSUSE-SU-2019:2550-1
OPENSUSE-SU-2019:2551-1
OPENSUSE-SU-2019_2550-1
OPENSUSE-SU-2019_2551-1
RHSA-2021:4426
RHSA-2021_4426
RLSA-2021:4426
SUSE-SU-2019:2997-1
SUSE-SU-2019:3094-1
SUSE-SU-2019_2997-1
USN-5477-1
USN-6099-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Ncurses