Memory Corruption Vulnerability in ncurses Affects Local Users
CVE-2023-29491
Key Information:
Badges
Summary
ncurses versions prior to 6.4 20230408 exhibit a vulnerability that permits local users of setuid applications to induce memory corruption. This occurs through the utilization of malformed data within a terminfo database file located in the user's home directory or accessed via environment variables like TERMINFO or TERM. This security flaw underscores the importance of maintaining updated ncurses installations to mitigate potential risks.
Get notified when SecurityVulnerability.io launches alerting π
Well keep you posted π§
News Articles
Uncursing the ncurses: Memory corruption vulnerabilities found in library | Microsoft Security Blog
A set of memory corruption vulnerabilities in the ncurses library could have allowed attackers to chain the vulnerabilities to elevate privileges and run code in the targeted program's context or perform other malicious actions.
1 year ago
Microsoft Flushes Out 'Ncurses' Gremlins
The maintainers of the widely used library recently patched multiple memory corruption vulnerabilities that attackers could have abused to, ahem, curse targets with malicious code and escalate privileges.
1 year ago
References
CVSS V3.1
Timeline
- πΎ
Exploit known to exist
- π°
First article discovered by Dark Reading
Vulnerability published
Vulnerability Reserved