[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251625

 
 

909

 
 

196370

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2023-29491Date: (C)2023-04-15   (M)2024-05-21


ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.8CVSS Score :
Exploit Score: 1.8Exploit Score:
Impact Score: 5.9Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector:
Attack Complexity: LOWAccess Complexity:
Privileges Required: LOWAuthentication:
User Interaction: NONEConfidentiality:
Scope: UNCHANGEDIntegrity:
Confidentiality: HIGHAvailability:
Integrity: HIGH 
Availability: HIGH 
  
Reference:
FEDORA-2024-96090dafaf
https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html
http://www.openwall.com/lists/oss-security/2023/04/19/11
http://www.openwall.com/lists/oss-security/2023/04/19/10
http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
https://security.netapp.com/advisory/ntap-20230517-0009/
https://support.apple.com/kb/HT213843
https://support.apple.com/kb/HT213844
https://support.apple.com/kb/HT213845
https://www.openwall.com/lists/oss-security/2023/04/12/5
https://www.openwall.com/lists/oss-security/2023/04/13/4

CWE    1
CWE-787
OVAL    22
oval:org.secpod.oval:def:2108136
oval:org.secpod.oval:def:508085
oval:org.secpod.oval:def:2600399
oval:org.secpod.oval:def:90208
...

© SecPod Technologies