CVE-2000-0963

5 documents5 sources
Severity
7.2HIGH
EPSS
0.1%
top 75.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 19
Latest updateApr 30

Description

Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages3 packages

NVDgnu/ncurses< 5.6
NVDredhat/linux6.2, 7.0+1
NVDimmunix/immunix6.2, 7.0_beta+1

Also affects: Freebsd 3.4, 3.5.1, 4.0, 4.1, 4.1.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4qvg-86rr-5qx2: Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS2022-04-30
CVEList
CVE-2000-0963: Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS2000-11-29

📋Vendor Advisories

1
Red Hat
security flaw2000-10-09

💬Community

1
Bugzilla
CVE-2000-0963 security flaw2018-08-16