Debian Ncurses vulnerabilities
28 known vulnerabilities affecting debian/ncurses.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM15LOW4
Vulnerabilities
Page 2 of 2
CVE-2017-13734P4MEDIUMCVSS 6.5fixed in ncurses 6.0+20170827-1 (bookworm)2017
CVE-2017-13734 [MEDIUM] CVE-2017-13734: ncurses - There is an illegal address access in the _nc_safe_strcat function in strings.c ...
There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 6.0+20170827-1)
bullseye: resolved (fixed in 6.0+20170827-1)
forky: resolved (fixed in 6.0+20170827-1)
sid: resolved (fixed in 6.0+20170827-1)
trixie: resolved (fixed in 6.0+20
debian
CVE-2023-50495P4MEDIUMCVSS 6.5fixed in ncurses 6.4+20230625-1 (forky)2023
CVE-2023-50495 [MEDIUM] CVE-2023-50495: ncurses - NCurse v6.4-20230418 was discovered to contain a segmentation fault via the comp...
NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.4+20230625-1)
sid: resolved (fixed in 6.4+20230625-1)
trixie: resolved (fixed in 6.4+20230625-1)
debian
CVE-2022-29458P4HIGHCVSS 7.1fixed in ncurses 6.3+20220423-1 (bookworm)2022
CVE-2022-29458 [HIGH] CVE-2022-29458: ncurses - ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation vio...
ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
Scope: local
bookworm: resolved (fixed in 6.3+20220423-1)
bullseye: resolved (fixed in 6.2+20201114-2+deb11u1)
forky: resolved (fixed in 6.3+20220423-1)
sid: resolved (fixed in 6.3+20220423-1)
trixie: resolved (fixe
debian
CVE-2019-17595P4LOWCVSS 5.4fixed in ncurses 6.1+20191019-1 (bookworm)2019
CVE-2019-17595 [MEDIUM] CVE-2019-17595: ncurses - There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_h...
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Scope: local
bookworm: resolved (fixed in 6.1+20191019-1)
bullseye: resolved (fixed in 6.1+20191019-1)
forky: resolved (fixed in 6.1+20191019-1)
sid: resolved (fixed in 6.1+20191019-1)
trixie: resolved (fixed in 6.1+20191019
debian
CVE-2018-19217P4MEDIUMCVSS 6.5fixed in ncurses 6.0+20170701-1 (bookworm)2018
CVE-2018-19217 [MEDIUM] CVE-2018-19217: ncurses - In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the f...
In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party
Scope: local
bookworm: resolved (fixed in 6.0+20170701-1)
bullseye:
debian
CVE-2019-17594P4LOWCVSS 5.3fixed in ncurses 6.1+20191019-1 (bookworm)2019
CVE-2019-17594 [MEDIUM] CVE-2019-17594: ncurses - There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/c...
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Scope: local
bookworm: resolved (fixed in 6.1+20191019-1)
bullseye: resolved (fixed in 6.1+20191019-1)
forky: resolved (fixed in 6.1+20191019-1)
sid: resolved (fixed in 6.1+20191019-1)
trixie: resolved (fixed in 6.1+201
debian
CVE-2018-19211P4LOWCVSS 5.5fixed in ncurses 6.1+20180210-3 (bookworm)2018
CVE-2018-19211 [MEDIUM] CVE-2018-19211: ncurses - In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry ...
In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
Scope: local
bookworm: resolved (fixed in 6.1+20180210-3)
bullseye: resolved (fixed in 6.1+20180210-3)
debian
CVE-2025-6141P4MEDIUMCVSS 4.8fixed in ncurses 6.5+20251115-2 (forky)2025
CVE-2025-6141 [MEDIUM] CVE-2025-6141: ncurses - A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified ...
A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommende
debian
← Previous2 / 2