ALT-PU-2023-7517-3
Closed vulnerabilities
Published: 2021-10-21
BDU:2023-00296
Уязвимость функции convert_strings компонента tinfo/read_entry.c библиотеки управления вводом-выводом на терминал Ncurses, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
Severity: HIGH (7.1)
Vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Severity: MEDIUM (6.6)
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:C
References:
Published: 2022-04-18
Modified: 2025-06-09
Modified: 2025-06-09
CVE-2022-29458
ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
Severity: MEDIUM (5.8)
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P
Severity: HIGH (7.1)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
References:
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://lists.debian.org/debian-lts-announce/2022/10/msg00037.html
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00014.html
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00016.html
- https://support.apple.com/kb/HT213488
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41
- https://lists.debian.org/debian-lts-announce/2022/10/msg00037.html
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00014.html
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00016.html
- https://support.apple.com/kb/HT213488
Closed bugs
Move /usr/bin/infocmp to termutils