Debian Ncurses vulnerabilities
28 known vulnerabilities affecting debian/ncurses.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM15LOW4
Vulnerabilities
Page 1 of 2
CVE-2017-10685P3CRITICALCVSS 9.8fixed in ncurses 6.0+20170701-1 (bookworm)2017
CVE-2017-10685 [CRITICAL] CVE-2017-10685: ncurses - In ncurses 6.0, there is a format string vulnerability in the fmt_entry function...
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
Scope: local
bookworm: resolved (fixed in 6.0+20170701-1)
bullseye: resolved (fixed in 6.0+20170701-1)
forky: resolved (fixed in 6.0+20170701-1)
sid: resolved (fixed in 6.0+20170701-1)
trixie: resolved (fixed in
debian
CVE-2017-10684P3CRITICALCVSS 9.8fixed in ncurses 6.0+20170708-1 (bookworm)2017
CVE-2017-10684 [CRITICAL] CVE-2017-10684: ncurses - In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function...
In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
Scope: local
bookworm: resolved (fixed in 6.0+20170708-1)
bullseye: resolved (fixed in 6.0+20170708-1)
forky: resolved (fixed in 6.0+20170708-1)
sid: resolved (fixed in 6.0+20170708-1)
trixie: resolved (fixed in
debian
CVE-2021-39537P3LOWCVSS 8.8fixed in ncurses 6.2+20200912-1 (bookworm)2021
CVE-2021-39537 [HIGH] CVE-2021-39537: ncurses - An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c ...
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 6.2+20200912-1)
bullseye: resolved (fixed in 6.2+20200912-1)
forky: resolved (fixed in 6.2+20200912-1)
sid: resolved (fixed in 6.2+20200912-1)
trixie: resolved (fixed in 6.2+20200912-1)
debian
CVE-2025-69720P3HIGHCVSS 7.3fixed in ncurses 6.6+20251231-1 (forky)2025
CVE-2025-69720 [HIGH] CVE-2025-69720: ncurses - The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based b...
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.6+20251231-1)
sid: resolved (fixed in 6.6+20251231-1)
trixie: open
debian
CVE-2023-29491P3HIGHCVSS 7.8fixed in ncurses 6.4-3 (bookworm)2023
CVE-2023-29491 [HIGH] CVE-2023-29491: ncurses - ncurses before 6.4 20230408, when used by a setuid application, allows local use...
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Scope: local
bookworm: resolved (fixed in 6.4-3)
bullseye: resolved (fixed in 6.2+20201114-2+deb11u2
debian
CVE-2017-13728P3HIGHCVSS 7.5fixed in ncurses 6.0+20170827-1 (bookworm)2017
CVE-2017-13728 [HIGH] CVE-2017-13728: ncurses - There is an infinite loop in the next_char function in comp_scan.c in ncurses 6....
There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 6.0+20170827-1)
bullseye: resolved (fixed in 6.0+20170827-1)
forky: resolved (fixed in 6.0+20170827-1)
sid: resolved (fixed in 6.0+20170827-1)
trixie: resolved
debian
CVE-2017-11112P3HIGHCVSS 7.5fixed in ncurses 6.0+20170701-1 (bookworm)2017
CVE-2017-11112 [HIGH] CVE-2017-11112: ncurses - In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_ac...
In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.
Scope: local
bookworm: resolved (fixed in 6.0+20170701-1)
bullseye: resolved (fixed in 6.0+20170701-1)
forky: resolved (fixed in
debian
CVE-2017-11113P4HIGHCVSS 7.5fixed in ncurses 6.0+20170701-1 (bookworm)2017
CVE-2017-11113 [HIGH] CVE-2017-11113: ncurses - In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry funct...
In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.
Scope: local
bookworm: resolved (fixed in 6.0+20170701-1)
bullseye: resolved (fixed in 6.0+20170701-1)
forky: resolved (fixed in 6.0+201
debian
CVE-2017-16879P4HIGHCVSS 7.8fixed in ncurses 6.0+20171125-1 (bookworm)2017
CVE-2017-16879 [HIGH] CVE-2017-16879: ncurses - Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry...
Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.
Scope: local
bookworm: resolved (fixed in 6.0+20171125-1)
bullseye: resolved (fixed in 6.0+20171125-1)
forky: resolv
debian
CVE-2020-19189P4MEDIUMCVSS 6.5fixed in ncurses 6.1+20191019-1 (bookworm)2020
CVE-2020-19189 [MEDIUM] CVE-2020-19189: ncurses - Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_en...
Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Scope: local
bookworm: resolved (fixed in 6.1+20191019-1)
bullseye: resolved (fixed in 6.1+20191019-1)
forky: resolved (fixed in 6.1+20191019-1)
sid: resolved (fixed in 6.1+20191019-1)
tr
debian
CVE-2020-19186P4MEDIUMCVSS 6.5fixed in ncurses 6.1+20191019-1 (bookworm)2020
CVE-2020-19186 [MEDIUM] CVE-2020-19186: ncurses - Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66...
Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Scope: local
bookworm: resolved (fixed in 6.1+20191019-1)
bullseye: resolved (fixed in 6.1+20191019-1)
forky: resolved (fixed in 6.1+20191019-1)
sid: resolved (fixed in 6.1+20191019-1)
trixie: res
debian
CVE-2020-19190P4MEDIUMCVSS 6.5fixed in ncurses 6.1+20191019-1 (bookworm)2020
CVE-2020-19190 [MEDIUM] CVE-2020-19190: ncurses - Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurs...
Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Scope: local
bookworm: resolved (fixed in 6.1+20191019-1)
bullseye: resolved (fixed in 6.1+20191019-1)
forky: resolved (fixed in 6.1+20191019-1)
sid: resolved (fixed in 6.1+20191019-1)
trixie: resolved (fi
debian
CVE-2017-13730P4MEDIUMCVSS 6.5fixed in ncurses 6.0+20170827-1 (bookworm)2017
CVE-2017-13730 [MEDIUM] CVE-2017-13730: ncurses - There is an illegal address access in the function _nc_read_entry_source() in pr...
There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 6.0+20170827-1)
bullseye: resolved (fixed in 6.0+20170827-1)
forky: resolved (fixed in 6.0+20170827-1)
sid: resolved (fixed in 6.0+20170827-1)
trixie: resolved (fixe
debian
CVE-2017-13732P4MEDIUMCVSS 6.5fixed in ncurses 6.0+20170827-1 (bookworm)2017
CVE-2017-13732 [MEDIUM] CVE-2017-13732: ncurses - There is an illegal address access in the function dump_uses() in progs/dump_ent...
There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 6.0+20170827-1)
bullseye: resolved (fixed in 6.0+20170827-1)
forky: resolved (fixed in 6.0+20170827-1)
sid: resolved (fixed in 6.0+20170827-1)
trixie: resolved (fixed in
debian
CVE-2017-13729P4MEDIUMCVSS 6.5fixed in ncurses 6.0+20170827-1 (bookworm)2017
CVE-2017-13729 [MEDIUM] CVE-2017-13729: ncurses - There is an illegal address access in the _nc_save_str function in alloc_entry.c...
There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 6.0+20170827-1)
bullseye: resolved (fixed in 6.0+20170827-1)
forky: resolved (fixed in 6.0+20170827-1)
sid: resolved (fixed in 6.0+20170827-1)
trixie: resolved (fixed in 6.0+20
debian
CVE-2017-13731P4MEDIUMCVSS 6.5fixed in ncurses 6.0+20170827-1 (bookworm)2017
CVE-2017-13731 [MEDIUM] CVE-2017-13731: ncurses - There is an illegal address access in the function postprocess_termcap() in pars...
There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 6.0+20170827-1)
bullseye: resolved (fixed in 6.0+20170827-1)
forky: resolved (fixed in 6.0+20170827-1)
sid: resolved (fixed in 6.0+20170827-1)
trixie: resolved (fixed
debian
CVE-2020-19187P4MEDIUMCVSS 6.5fixed in ncurses 6.1+20191019-1 (bookworm)2020
CVE-2020-19187 [MEDIUM] CVE-2020-19187: ncurses - Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 i...
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Scope: local
bookworm: resolved (fixed in 6.1+20191019-1)
bullseye: resolved (fixed in 6.1+20191019-1)
forky: resolved (fixed in 6.1+20191019-1)
sid: resolved (fixed in 6.1+20191019-1)
trixie: resol
debian
CVE-2020-19185P4MEDIUMCVSS 6.5fixed in ncurses 6.1+20191019-1 (bookworm)2020
CVE-2020-19185 [MEDIUM] CVE-2020-19185: ncurses - Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:...
Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Scope: local
bookworm: resolved (fixed in 6.1+20191019-1)
bullseye: resolved (fixed in 6.1+20191019-1)
forky: resolved (fixed in 6.1+20191019-1)
sid: resolved (fixed in 6.1+20191019-1)
trixie:
debian
CVE-2020-19188P4MEDIUMCVSS 6.5fixed in ncurses 6.1+20191019-1 (bookworm)2020
CVE-2020-19188 [MEDIUM] CVE-2020-19188: ncurses - Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 i...
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Scope: local
bookworm: resolved (fixed in 6.1+20191019-1)
bullseye: resolved (fixed in 6.1+20191019-1)
forky: resolved (fixed in 6.1+20191019-1)
sid: resolved (fixed in 6.1+20191019-1)
trixie: resol
debian
CVE-2017-13733P4MEDIUMCVSS 6.5fixed in ncurses 6.0+20170902-1 (bookworm)2017
CVE-2017-13733 [MEDIUM] CVE-2017-13733: ncurses - There is an illegal address access in the fmt_entry function in progs/dump_entry...
There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 6.0+20170902-1)
bullseye: resolved (fixed in 6.0+20170902-1)
forky: resolved (fixed in 6.0+20170902-1)
sid: resolved (fixed in 6.0+20170902-1)
trixie: resolved (fixed in 6.
debian
1 / 2Next →