Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-29491

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.9%
CVSS Severity
CVSS v3 Score 7.8
References
Products affected by CVE-2023-29491
  • Gnu » Ncurses » Version: N/A
    cpe:2.3:a:gnu:ncurses:-
  • Gnu » Ncurses » Version: 4.0
    cpe:2.3:a:gnu:ncurses:4.0
  • Gnu » Ncurses » Version: 4.1
    cpe:2.3:a:gnu:ncurses:4.1
  • Gnu » Ncurses » Version: 4.2
    cpe:2.3:a:gnu:ncurses:4.2
  • Gnu » Ncurses » Version: 5.0
    cpe:2.3:a:gnu:ncurses:5.0
  • Gnu » Ncurses » Version: 5.1
    cpe:2.3:a:gnu:ncurses:5.1
  • Gnu » Ncurses » Version: 5.2.
    cpe:2.3:a:gnu:ncurses:5.2.
  • Gnu » Ncurses » Version: 5.3
    cpe:2.3:a:gnu:ncurses:5.3
  • Gnu » Ncurses » Version: 5.4
    cpe:2.3:a:gnu:ncurses:5.4
  • Gnu » Ncurses » Version: 5.5
    cpe:2.3:a:gnu:ncurses:5.5
  • Gnu » Ncurses » Version: 5.6
    cpe:2.3:a:gnu:ncurses:5.6
  • Gnu » Ncurses » Version: 5.7
    cpe:2.3:a:gnu:ncurses:5.7
  • Gnu » Ncurses » Version: 5.8
    cpe:2.3:a:gnu:ncurses:5.8
  • Gnu » Ncurses » Version: 5.9
    cpe:2.3:a:gnu:ncurses:5.9
  • Gnu » Ncurses » Version: 6.0
    cpe:2.3:a:gnu:ncurses:6.0
  • Gnu » Ncurses » Version: 6.1
    cpe:2.3:a:gnu:ncurses:6.1
  • Gnu » Ncurses » Version: 6.1.20180414
    cpe:2.3:a:gnu:ncurses:6.1.20180414
  • Gnu » Ncurses » Version: 6.1.20191012
    cpe:2.3:a:gnu:ncurses:6.1.20191012
  • Gnu » Ncurses » Version: 6.2
    cpe:2.3:a:gnu:ncurses:6.2
  • Gnu » Ncurses » Version: 6.3
    cpe:2.3:a:gnu:ncurses:6.3


Contact Us

Shodan ® - All rights reserved