Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29491


ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.


Published

2023-04-14T01:15:08.570

Last Modified

2024-11-21T07:57:09.933

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gnu ncurses < 6.4 Yes

References