Do your applications use this vulnerable package?
Test your applications
Overview
In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
References
CVSS Score
5.5
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2018-19211
- CWE
- CWE-476
- Snyk ID
- SNYK-DEBIAN8-NCURSES-343146
- Disclosed
- 12 Nov, 2018
- Published
- 12 Nov, 2018