Buffer Overflow Vulnerability in ncurses Affects Multiple Platforms
CVE-2020-19190

6.5MEDIUM

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
22 August 2023

Summary

A buffer overflow vulnerability exists in the _nc_find_entry function located in tinfo/comp_hash.c:70 of the ncurses library version 6.1. This flaw allows remote attackers to send specially crafted commands to compromise the application, potentially resulting in a denial of service. Exploitation of this vulnerability can lead to disruption of service and hinder the application’s functioning. Proper input validation and updates to affected versions are critical for maintaining security.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.