CVE-2022-29458
גבוהה 7.1
תיאור (מקור, אנגלית)
ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
מדדים
- CVSS 3.1
-
7.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-125
מוצרים מושפעים
gnu: ncurses; invisible-island: ncurses; apple: macos; debian: debian linux
קישורים
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00014.html ExploitMailing ListVendor Advisory
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00016.html Mailing ListVendor Advisory
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00014.html ExploitMailing ListVendor Advisory
- https://lists.gnu.org/archive/html/bug-ncurses/2022-04/msg00016.html Mailing ListVendor Advisory
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41 Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00037.html Mailing ListThird Party Advisory
- https://support.apple.com/kb/HT213488 Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/28
- http://seclists.org/fulldisclosure/2022/Oct/41 Mailing ListThird Party Advisory