CVE-2023-29491
גבוהה 7.8
תיאור (מקור, אנגלית)
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-787
מוצרים מושפעים
invisible-island: ncurses
קישורים
- http://www.openwall.com/lists/oss-security/2023/04/19/10 Mailing ListPatchThird Party Advisory
- https://www.openwall.com/lists/oss-security/2023/04/13/4 Mailing ListPatch
- http://www.openwall.com/lists/oss-security/2023/04/19/10 Mailing ListPatchThird Party Advisory
- https://www.openwall.com/lists/oss-security/2023/04/13/4 Mailing ListPatch
- http://www.openwall.com/lists/oss-security/2023/04/19/11 ExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/04/19/11 ExploitMailing ListThird Party Advisory
- http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec1…
- https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…
- https://security.netapp.com/advisory/ntap-20230517-0009/