cbcvebase.
CVE-2023-29491
published 2023-04-14

CVE-2023-29491: ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

Affected

20 ranges
VendorProductVersion rangeFixed in
applemacos_big_sur
applemacos_monterey
applemacos_ventura
debianncurses< ncurses 6.4-3 (bookworm)ncurses 6.4-3 (bookworm)
gnuncurses< 6.46.4
gnuncurses>= 0 < 6.2+20201114-2+deb11u26.2+20201114-2+deb11u2
gnuncurses>= 0 < 6.4-36.4-3
gnuncurses>= 0 < 6.4-36.4-3
gnuncurses>= 0 < 6.4-36.4-3
gnuncurses>= 0 < 6.1-1ubuntu1.18.04.16.1-1ubuntu1.18.04.1
gnuncurses>= 0 < 6.2-0ubuntu2.16.2-0ubuntu2.1
gnuncurses>= 0 < 6.3-2ubuntu0.16.3-2ubuntu0.1
gnuncurses>= 0 < 5.9+20140118-1ubuntu1+esm35.9+20140118-1ubuntu1+esm3
gnuncurses>= 0 < 6.0+20160213-1ubuntu1+esm36.0+20160213-1ubuntu1+esm3
msrccbl2_ncurses_6.4-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_ncurses_6.4-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH