ALT-PU-2020-3296-1
Closed vulnerabilities
Published: 2019-10-13
BDU:2020-01853
Уязвимость функции _nc_find_entry библиотеки ncurses, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Severity: MEDIUM (5.3)
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References:
Published: 2019-10-13
BDU:2020-01854
Уязвимость функции fmt_entry function библиотеки ncurses, позволяющая нарушителю раскрыть защищаемую информацию и вызвать отказ в обслуживании
Severity: MEDIUM (5.4)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
References:
Published: 2019-10-15
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-17594
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Severity: MEDIUM (5.3)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References:
- openSUSE-SU-2019:2551
- openSUSE-SU-2019:2551
- openSUSE-SU-2019:2550
- openSUSE-SU-2019:2550
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00017.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00017.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00045.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00045.html
- GLSA-202101-28
- GLSA-202101-28
Published: 2019-10-15
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-17595
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Severity: MEDIUM (5.4)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
References:
- openSUSE-SU-2019:2551
- openSUSE-SU-2019:2551
- openSUSE-SU-2019:2550
- openSUSE-SU-2019:2550
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00013.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00013.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00045.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00045.html
- GLSA-202101-28
- GLSA-202101-28
Published: 2021-09-20
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-39537
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
Severity: HIGH (8.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup
- http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup
- 20221030 APPLE-SA-2022-10-24-2 macOS Ventura 13
- 20221030 APPLE-SA-2022-10-24-2 macOS Ventura 13
- 20221030 APPLE-SA-2022-10-27-5 Additional information for APPLE-SA-2022-10-24-2 macOS Ventura 13
- 20221030 APPLE-SA-2022-10-27-5 Additional information for APPLE-SA-2022-10-24-2 macOS Ventura 13
- 20221030 APPLE-SA-2022-10-27-7 Additional information for APPLE-SA-2022-09-12-4 macOS Monterey 12.6
- 20221030 APPLE-SA-2022-10-27-7 Additional information for APPLE-SA-2022-09-12-4 macOS Monterey 12.6
- 20221030 APPLE-SA-2022-10-27-9 Additional information for APPLE-SA-2022-09-12-3 macOS Big Sur 11.7
- 20221030 APPLE-SA-2022-10-27-9 Additional information for APPLE-SA-2022-09-12-3 macOS Big Sur 11.7
- [debian-lts-announce] 20231203 [SECURITY] [DLA 3682-1] ncurses security update
- [debian-lts-announce] 20231203 [SECURITY] [DLA 3682-1] ncurses security update
- https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html
- https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html
- https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html
- https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html
- https://security.netapp.com/advisory/ntap-20230427-0012/
- https://security.netapp.com/advisory/ntap-20230427-0012/
- https://support.apple.com/kb/HT213443
- https://support.apple.com/kb/HT213443
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213444
- https://support.apple.com/kb/HT213488
- https://support.apple.com/kb/HT213488