An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
References
Link | Resource |
---|---|
https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html | Exploit Mailing List Vendor Advisory |
https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html | Mailing List Vendor Advisory |
http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup | Patch Third Party Advisory |
https://support.apple.com/kb/HT213488 | Third Party Advisory |
https://support.apple.com/kb/HT213443 | Third Party Advisory |
https://support.apple.com/kb/HT213444 | Third Party Advisory |
http://seclists.org/fulldisclosure/2022/Oct/41 | Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2022/Oct/28 | Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2022/Oct/43 | Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2022/Oct/45 | Mailing List Third Party Advisory |
Information
Published : 2021-09-20 09:15
Updated : 2022-12-06 17:38
NVD link : CVE-2021-39537
Mitre link : CVE-2021-39537
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
apple
- mac_os_x
- macos
gnu
- ncurses