CVE-2019-15548Improper Restriction of Operations within the Bounds of a Memory Buffer in Project Ncurses

Severity
9.8CRITICALNVD
EPSS
0.6%
top 30.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateAug 25

Description

An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

crates.iognu/ncurses5.101.0+1

🔴Vulnerability Details

6
OSV
Mishandling of format strings in ncurses2021-08-25
GHSA
Buffer overflow and format vulnerabilities in ncurses2021-08-25
OSV
Buffer overflow and format vulnerabilities in ncurses2021-08-25
OSV
CVE-2019-15548: An issue was discovered in the ncurses crate through 52019-08-26
CVEList
CVE-2019-15548: An issue was discovered in the ncurses crate through 52019-08-26
CVE-2019-15548 — Ncurses Project Ncurses vulnerability | cvebase