Out-of-Bounds Affecting ncurses-base package, versions *
Threat Intelligence
EPSS
0.06% (24th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS7-NCURSESBASE-1995930
- published 26 Jul 2021
- disclosed 11 Oct 2019
How to fix?
There is no fixed version for Centos:7 ncurses-base.
NVD Description
Note: Versions mentioned in the description apply only to the upstream ncurses-base package and not the ncurses-base package as distributed by Centos.
See How to fix? for Centos:7 relevant fixed versions and status.
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
References
- https://access.redhat.com/security/cve/CVE-2019-17594
- https://security.gentoo.org/glsa/202101-28
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00017.html
- https://lists.gnu.org/archive/html/bug-ncurses/2019-10/msg00045.html
- https://access.redhat.com/errata/RHSA-2021:4426
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00061.html
CVSS Scores
version 3.1