CVE-2023-29491
published 2023-04-14CVE-2023-29491: ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.92%
56.5th percentile
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | macos_ventura | — | — |
| debian | ncurses | < ncurses 6.4-3 (bookworm) | ncurses 6.4-3 (bookworm) |
| gnu | ncurses | < 6.4 | 6.4 |
| gnu | ncurses | >= 0 < 6.2+20201114-2+deb11u2 | 6.2+20201114-2+deb11u2 |
| gnu | ncurses | >= 0 < 6.4-3 | 6.4-3 |
| gnu | ncurses | >= 0 < 6.4-3 | 6.4-3 |
| gnu | ncurses | >= 0 < 6.4-3 | 6.4-3 |
| gnu | ncurses | >= 0 < 6.1-1ubuntu1.18.04.1 | 6.1-1ubuntu1.18.04.1 |
| gnu | ncurses | >= 0 < 6.2-0ubuntu2.1 | 6.2-0ubuntu2.1 |
| gnu | ncurses | >= 0 < 6.3-2ubuntu0.1 | 6.3-2ubuntu0.1 |
| gnu | ncurses | >= 0 < 5.9+20140118-1ubuntu1+esm3 | 5.9+20140118-1ubuntu1+esm3 |
| gnu | ncurses | >= 0 < 6.0+20160213-1ubuntu1+esm3 | 6.0+20160213-1ubuntu1+esm3 |
| msrc | cbl2_ncurses_6.4-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_ncurses_6.4-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (NCURSES) — CVE-2023-29491
vendor_oracle·2023-10-15·CVSS 7.8
CVE-2023-29491 [HIGH] Oracle Oracle Communications Risk Matrix: Install/Upgrade (NCURSES) — CVE-2023-29491
Oracle Oracle Communications Risk Matrix: Install/Upgrade (NCURSES) vulnerability
CVE: CVE-2023-29491
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2023 (OCT 2023)
Apple
CVE-2023-29491: macOS Big Sur 11.7.9
vendor_apple·2023-07-24·CVSS 7.8
CVE-2023-29491 [HIGH] CVE-2023-29491: macOS Big Sur 11.7.9
Apple Security Update: About the security content of macOS Big Sur 11.7.9
Product: macOS Big Sur
Version: 11.7.9
CVE: CVE-2023-29491
Component: Music
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved validation of symlinks.
Apple
CVE-2023-29491: macOS Monterey 12.6.8
vendor_apple·2023-07-24·CVSS 6.1
CVE-2023-29491 [MEDIUM] CVE-2023-29491: macOS Monterey 12.6.8
Apple Security Update: About the security content of macOS Monterey 12.6.8
Product: macOS Monterey
Version: 12.6.8
CVE: CVE-2023-29491
Component: CVE-2023-1916
Impact: An app may cause unexpected app termination or arbitrary code execution
Description: A memory corruption issue was addressed with improved validation.
Apple
CVE-2023-29491: macOS Ventura 13.5
vendor_apple·2023-07-24·CVSS 7.8
CVE-2023-29491 [HIGH] CVE-2023-29491: macOS Ventura 13.5
Apple Security Update: About the security content of macOS Ventura 13.5
Product: macOS Ventura
Version: 13.5
CVE: CVE-2023-29491
Component: Music
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved validation of symlinks.
Ubuntu
ncurses vulnerabilities
vendor_ubuntu·2023-05-23·CVSS 5.3
CVE-2021-39537 [MEDIUM] ncurses vulnerabilities
Title: ncurses vulnerabilities
Summary: Several security issues were fixed in ncurses.
It was discovered that ncurses was incorrectly performing bounds
checks when processing invalid hashcodes. An attacker could possibly
use this issue to cause a denial of service or to expose sensitive
information. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-17594)
It was discovered that ncurses was incorrectly handling
end-of-string characters when processing terminfo and termcap files.
An attacker could possibly use this issue to cause a denial of
service or to expose sensitive information. This issue only affected
Ubuntu 18.04 LTS. (CVE-2019-17595)
It was discovered that ncurses was incorrectly handling
end-of-string characters when converting between termcap and
terminfo formats. An attac
Red Hat
ncurses: Local users can trigger security-relevant memory corruption via malformed data
vendor_redhat·2023-04-12·CVSS 7.8
CVE-2023-29491 [HIGH] CWE-787 ncurses: Local users can trigger security-relevant memory corruption via malformed data
ncurses: Local users can trigger security-relevant memory corruption via malformed data
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
A vulnerability was found in ncurses and occurs when used by a setuid application. This flaw allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Statement: The impact of this CVE is rated Moderate for several reasons which make it difficult to exploit or limited consequences:
* The only outcome i
Microsoft
ncurses before 6.4 20230408 when used by a setuid application allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.t
vendor_msrc·2023-04-11·CVSS 7.8
CVE-2023-29491 [HIGH] CWE-787 ncurses before 6.4 20230408 when used by a setuid application allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.t
ncurses before 6.4 20230408 when used by a setuid application allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. I
Debian
CVE-2023-29491: ncurses - ncurses before 6.4 20230408, when used by a setuid application, allows local use...
vendor_debian·2023·CVSS 7.8
CVE-2023-29491 [HIGH] CVE-2023-29491: ncurses - ncurses before 6.4 20230408, when used by a setuid application, allows local use...
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Scope: local
bookworm: resolved (fixed in 6.4-3)
bullseye: resolved (fixed in 6.2+20201114-2+deb11u2)
forky: resolved (fixed in 6.4-3)
sid: resolved (fixed in 6.4-3)
trixie: resolved (fixed in 6.4-3)
OSV
ncurses vulnerabilities
osv·2023-05-23·CVSS 5.3
CVE-2019-17594 [MEDIUM] ncurses vulnerabilities
ncurses vulnerabilities
It was discovered that ncurses was incorrectly performing bounds
checks when processing invalid hashcodes. An attacker could possibly
use this issue to cause a denial of service or to expose sensitive
information. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-17594)
It was discovered that ncurses was incorrectly handling
end-of-string characters when processing terminfo and termcap files.
An attacker could possibly use this issue to cause a denial of
service or to expose sensitive information. This issue only affected
Ubuntu 18.04 LTS. (CVE-2019-17595)
It was discovered that ncurses was incorrectly handling
end-of-string characters when converting between termcap and
terminfo formats. An attacker could possibly use this issue to cause
a denial of service o
GHSA
GHSA-vh2x-5rx6-qqhv: ncurses before 6
ghsa_unreviewed·2023-04-14
CVE-2023-29491 [HIGH] CWE-787 GHSA-vh2x-5rx6-qqhv: ncurses before 6
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
OSV
CVE-2023-29491: ncurses before 6
osv·2023-04-14·CVSS 7.8
CVE-2023-29491 [HIGH] CVE-2023-29491: ncurses before 6
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
No detection rules found.
No public exploits indexed.
http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56http://www.openwall.com/lists/oss-security/2023/04/19/10http://www.openwall.com/lists/oss-security/2023/04/19/11https://lists.debian.org/debian-lts-announce/2023/12/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/https://security.netapp.com/advisory/ntap-20230517-0009/https://support.apple.com/kb/HT213843https://support.apple.com/kb/HT213844https://support.apple.com/kb/HT213845https://www.openwall.com/lists/oss-security/2023/04/12/5https://www.openwall.com/lists/oss-security/2023/04/13/4http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56http://www.openwall.com/lists/oss-security/2023/04/19/10http://www.openwall.com/lists/oss-security/2023/04/19/11https://lists.debian.org/debian-lts-announce/2023/12/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/https://lists.fedoraproject.org/archives/list/[email protected]/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/https://security.netapp.com/advisory/ntap-20230517-0009/https://support.apple.com/kb/HT213843https://support.apple.com/kb/HT213844https://support.apple.com/kb/HT213845https://www.openwall.com/lists/oss-security/2023/04/12/5https://www.openwall.com/lists/oss-security/2023/04/13/4
2023-04-14
Published