CVE-2021-39537
גבוהה 8.8
תיאור (מקור, אנגלית)
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-787
מוצרים מושפעים
invisible-island: ncurses; apple: mac os x; apple: macos
קישורים
- https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html ExploitMailing ListVendor Advisory
- https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html Mailing ListVendor Advisory
- https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html ExploitMailing ListVendor Advisory
- https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html Mailing ListVendor Advisory
- http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses… PatchThird Party Advisory
- http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses… PatchThird Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/28 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/41 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/43 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/45 Mailing ListThird Party Advisory