Vulnerabilities
Vulnerable Software
Gnu:  >> Ncurses  >> 6.1  Security Vulnerabilities
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVSS Score
5.4
EPSS Score
0.001
Published
2019-10-14
In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
CVSS Score
5.5
EPSS Score
0.003
Published
2018-11-12
In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party
CVSS Score
6.5
EPSS Score
0.004
Published
2018-11-12


Contact Us

Shodan ® - All rights reserved