CVE-2020-19188
published 2023-08-22CVE-2020-19188: Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.40%
69.5th percentile
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_monterey | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| debian | ncurses | < ncurses 6.1+20191019-1 (bookworm) | ncurses 6.1+20191019-1 (bookworm) |
| gnu | ncurses | — | — |
| gnu | ncurses | >= 0 < 6.1+20191019-1 | 6.1+20191019-1 |
| gnu | ncurses | >= 0 < 6.1+20191019-1 | 6.1+20191019-1 |
| gnu | ncurses | >= 0 < 6.1+20191019-1 | 6.1+20191019-1 |
| gnu | ncurses | >= 0 < 6.1+20191019-1 | 6.1+20191019-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-19188: Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry
osv·2023-08-22·CVSS 6.5
CVE-2020-19188 [MEDIUM] CVE-2020-19188: Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
GHSA
GHSA-8jj7-mqrc-fff9: Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry
ghsa_unreviewed·2023-08-22
CVE-2020-19188 [MEDIUM] CWE-787 GHSA-8jj7-mqrc-fff9: Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Apple
CVE-2020-19188: macOS Monterey 12.7.2
vendor_apple·2023-12-11·CVSS 6.5
CVE-2020-19188 [MEDIUM] CVE-2020-19188: macOS Monterey 12.7.2
Apple Security Update: About the security content of macOS Monterey 12.7.2
Product: macOS Monterey
Version: 12.7.2
CVE: CVE-2020-19188
Component: CVE-2020-19188
Apple
CVE-2020-19188: macOS Ventura 13.6.3
vendor_apple·2023-12-11·CVSS 6.5
CVE-2020-19188 [MEDIUM] CVE-2020-19188: macOS Ventura 13.6.3
Apple Security Update: About the security content of macOS Ventura 13.6.3
Product: macOS Ventura
Version: 13.6.3
CVE: CVE-2020-19188
Component: CVE-2020-19188
Apple
CVE-2020-19188: macOS Sonoma 14.2
vendor_apple·2023-12-11·CVSS 6.5
CVE-2020-19188 [MEDIUM] CVE-2020-19188: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2020-19188
Component: CVE-2020-19188
Debian
CVE-2020-19188: ncurses - Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 i...
vendor_debian·2020·CVSS 6.5
CVE-2020-19188 [MEDIUM] CVE-2020-19188: ncurses - Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 i...
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Scope: local
bookworm: resolved (fixed in 6.1+20191019-1)
bullseye: resolved (fixed in 6.1+20191019-1)
forky: resolved (fixed in 6.1+20191019-1)
sid: resolved (fixed in 6.1+20191019-1)
trixie: resolved (fixed in 6.1+20191019-1)
Red Hat
ncurses: Stack buffer overflow in fmt_entry function in progs/dump_entry.c:1116
vendor_redhat·2019-05-03·CVSS 6.5
CVE-2020-19188 [MEDIUM] CWE-121 ncurses: Stack buffer overflow in fmt_entry function in progs/dump_entry.c:1116
ncurses: Stack buffer overflow in fmt_entry function in progs/dump_entry.c:1116
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
A flaw was found in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a stack-based buffer overflow, resulting in an application crash, leading to a denial of service.
Statement: Red Hat Product Security has rated this issue as having a Low security impact because processing terminfo descriptions in the source form should be handled the same way as executable files or source code of any programming language. Users are not supposed to use untrusted terminfo descriptions.
The ncurses library shipped with
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2023/Dec/10http://seclists.org/fulldisclosure/2023/Dec/11http://seclists.org/fulldisclosure/2023/Dec/9https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.mdhttps://security.netapp.com/advisory/ntap-20231006-0005/https://support.apple.com/kb/HT214036https://support.apple.com/kb/HT214037https://support.apple.com/kb/HT214038http://seclists.org/fulldisclosure/2023/Dec/10http://seclists.org/fulldisclosure/2023/Dec/11http://seclists.org/fulldisclosure/2023/Dec/9https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.mdhttps://security.netapp.com/advisory/ntap-20231006-0005/https://support.apple.com/kb/HT214036https://support.apple.com/kb/HT214037https://support.apple.com/kb/HT214038
2023-08-22
Published