CVE-2022-29458
published 2022-04-18CVE-2022-29458: ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 13.0 | 13.0 |
| apple | macos_ventura | — | — |
| debian | debian_linux | — | — |
| debian | ncurses | < ncurses 6.3+20220423-1 (bookworm) | ncurses 6.3+20220423-1 (bookworm) |
| gnu | ncurses | < 6.3 | 6.3 |
| gnu | ncurses | — | — |
| gnu | ncurses | >= 0 < 6.2+20201114-2+deb11u1 | 6.2+20201114-2+deb11u1 |
| gnu | ncurses | >= 0 < 6.3+20220423-1 | 6.3+20220423-1 |
| gnu | ncurses | >= 0 < 6.3+20220423-1 | 6.3+20220423-1 |
| gnu | ncurses | >= 0 < 6.3+20220423-1 | 6.3+20220423-1 |
| gnu | ncurses | >= 0 < 6.1-1ubuntu1.18.04.1 | 6.1-1ubuntu1.18.04.1 |
| gnu | ncurses | >= 0 < 6.2-0ubuntu2.1 | 6.2-0ubuntu2.1 |
| gnu | ncurses | >= 0 < 6.3-2ubuntu0.1 | 6.3-2ubuntu0.1 |
| gnu | ncurses | >= 0 < 5.9+20140118-1ubuntu1+esm3 | 5.9+20140118-1ubuntu1+esm3 |
| gnu | ncurses | >= 0 < 5.9+20140118-1ubuntu1+esm2 | 5.9+20140118-1ubuntu1+esm2 |
| gnu | ncurses | >= 0 < 6.0+20160213-1ubuntu1+esm3 | 6.0+20160213-1ubuntu1+esm3 |
| gnu | ncurses | >= 0 < 6.0+20160213-1ubuntu1+esm2 | 6.0+20160213-1ubuntu1+esm2 |
| msrc | cbl2_ncurses_6.3-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_ncurses_6.3-2_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv7.8HIGH