Your submission was sent successfully! Close

CVE-2017-16879

Published: 22 November 2017

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.

Priority

Negligible

CVSS 3 base score: 7.8

Status

Package Release Status
ncurses
Launchpad, Ubuntu, Debian
artful Ignored
(reached end-of-life)
bionic Not vulnerable
(6.1-1ubuntu1.18.04)
cosmic Not vulnerable
(6.1-1ubuntu1.18.04)
disco Not vulnerable
(6.1-1ubuntu1.18.04)
eoan Not vulnerable
(6.1-1ubuntu1.18.04)
focal Not vulnerable
(6.1-1ubuntu1.18.04)
groovy Not vulnerable
(6.1-1ubuntu1.18.04)
hirsute Not vulnerable
(6.1-1ubuntu1.18.04)
impish Not vulnerable
(6.1-1ubuntu1.18.04)
jammy Not vulnerable
(6.1-1ubuntu1.18.04)
precise Ignored
(end of ESM support, was needs-triage)
trusty
Released (5.9+20140118-1ubuntu1+esm2)
upstream
Released (6.0+20171125-1)
xenial
Released (6.0+20160213-1ubuntu1+esm2)
zesty Ignored
(reached end-of-life)