CVE-2017-10685

Published: 29 June 2017

In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.

Priority

Negligible

CVSS 3 base score: 9.8

Status

Package Release Status
ncurses
Launchpad, Ubuntu, Debian
Upstream
Released (6.0+20170708-1)
Ubuntu 20.10 (Groovy Gorilla) Not vulnerable
(6.1-1ubuntu1)
Ubuntu 20.04 LTS (Focal Fossa) Not vulnerable
(6.1-1ubuntu1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(6.1-1ubuntu1)
Ubuntu 16.04 LTS (Xenial Xerus) Needed

Ubuntu 14.04 ESM (Trusty Tahr) Needed

This vulnerability is mitigated in part by the use of gcc's stack protector in Ubuntu.

Notes

AuthorNote
mdeslaur
Red Hat considers this issue as a duplicate of CVE-2017-10684.

References

Bugs