GNU Ncurses 4.0

CPE Details

GNU Ncurses 4.0
4.0
2018-10-30
12h32 +00:00
2018-10-30
12h32 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gnu:ncurses:4.0:*:*:*:*:*:*:*

Informations

Vendor

gnu

Product

ncurses

Version

4.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-29491 2023-04-13 22h00 +00:00 ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
7.8
High
CVE-2022-29458 2022-04-17 22h00 +00:00 ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
7.1
High
CVE-2021-39537 2021-09-19 22h00 +00:00 An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
8.8
High
CVE-2019-17594 2019-10-14 18h43 +00:00 There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
5.3
Medium
CVE-2019-17595 2019-10-14 18h42 +00:00 There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
5.4
Medium
CVE-2002-0062 2003-04-02 03h00 +00:00 Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
7.2
CVE-2000-0963 2000-11-29 04h00 +00:00 Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.
7.2