Denial of Service Vulnerability in ncurses 6.0 by The Ncurses Developers
CVE-2017-13729

6.5MEDIUM

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
29 August 2017

Summary

In ncurses 6.0, the _nc_save_str function in alloc_entry.c contains an illegal address access issue, which may allow an attacker to mount a remote denial of service attack. Exploiting this vulnerability could potentially disrupt service availability and render affected systems unusable. It is essential for users to apply the necessary updates and patches to mitigate this risk.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.