Out-of-bounds Read
Affecting ncurses package, versions <6.1+20181013-2+deb10u2
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
References
CVSS Score
5.3
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityLow
-
AvailabilityLow
- CVE
- CVE-2019-17594
- CWE
- CWE-125
- Snyk ID
- SNYK-DEBIAN10-NCURSES-473141
- Disclosed
- 14 Oct, 2019
- Published
- 15 Oct, 2019