Severity
6.5MEDIUM
EPSS
1.9%
top 16.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22
Latest updateDec 11

Description

Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Debianncurses< 6.1+20191019-1+3
NVDgnu/ncurses6.1

Also affects: Debian Linux 10.0

🔴Vulnerability Details

3
GHSA
GHSA-gx38-wj66-8wfr: Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry2023-08-22
OSV
CVE-2020-19189: Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry2023-08-22
CVEList
CVE-2020-19189: Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry2023-08-22

📋Vendor Advisories

6
Apple
CVE-2020-19189: macOS Ventura 13.6.32023-12-11
Apple
CVE-2020-19189: macOS Monterey 12.7.22023-12-11
Apple
CVE-2020-19189: macOS Sonoma 14.22023-12-11
Ubuntu
ncurses vulnerability2023-10-24
Debian
CVE-2020-19189: ncurses - Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_en...2020
CVE-2020-19189 (MEDIUM CVSS 6.5) | Buffer Overflow vulnerability in po | cvebase.io