MGASA-2018-0001
Dashboard / Vulnerabilities / MGASA-2018-0001
MGASA-2018-0001
Summary: Updated ncurses packages fix security vulnerabilities
Details: Possible RCE via stack-based buffer overflow in the fmt_entry function (CVE-2017-10684). Possible RCE with format string vulnerability in the fmt_entry function (CVE-2017-10685). Illegal address access in append_acs (CVE-2017-11112). Dereferencing NULL pointer in _nc_parse_entry (CVE-2017-11113).
References: https://advisories.mageia.org/MGASA-2018-0001.html, https://bugs.mageia.org/show_bug.cgi?id=21197, https://lists.opensuse.org/opensuse-updates/2017-07/msg00071.html, https://lists.opensuse.org/opensuse-updates/2017-08/msg00048.html
Affected packages
Package
Name: ncurses
Purl: pkg:rpm/mageia/ncurses?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
