ALT-PU-2023-3798-1
Closed vulnerabilities
Published: 2021-10-21
BDU:2023-00296
Уязвимость функции convert_strings компонента tinfo/read_entry.c библиотеки управления вводом-выводом на терминал Ncurses, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
Severity: HIGH (7.1)
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
References:
Published: 2022-04-19
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-29458
ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
Severity: HIGH (7.1)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
References:
- 20221030 APPLE-SA-2022-10-24-2 macOS Ventura 13
- 20221030 APPLE-SA-2022-10-24-2 macOS Ventura 13
- 20221030 APPLE-SA-2022-10-27-5 Additional information for APPLE-SA-2022-10-24-2 macOS Ventura 13
- 20221030 APPLE-SA-2022-10-27-5 Additional information for APPLE-SA-2022-10-24-2 macOS Ventura 13
- [debian-lts-announce] 20221029 [SECURITY] [DLA 3167-1] ncurses security update
- [debian-lts-announce] 20221029 [SECURITY] [DLA 3167-1] ncurses security update
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00014.html
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00014.html
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00016.html
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00016.html
- https://support.apple.com/kb/HT213488
- https://support.apple.com/kb/HT213488
Closed bugs
Move /usr/bin/infocmp to termutils