CVE detail
CVE-2023-29491
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
Microsoft has discovered a set of memory corruption vulnerabilities in the ncurses library that provides a programming interface for writing text-based user interfaces (TUI) or console applications with a graphical appearance. Collectively identified as CVE-2023-29491 with a CVSS score of 7.8, the vulnerabilities can allow attackers to gain unauthorized access to systems and data by […]
newswww.csoonline.comSep 18, 2023, 12:30 PM- https://lists.fedoraproject.org/archives/list/[email protected]/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgApr 14, 2023, 1:15 AM - https://www.openwall.com/lists/oss-security/2023/04/13/4www.openwall.com
No excerpt available.
Exploitwww.openwall.comApr 14, 2023, 1:15 AM - https://www.openwall.com/lists/oss-security/2023/04/12/5www.openwall.com
No excerpt available.
Exploitwww.openwall.comApr 14, 2023, 1:15 AM - https://support.apple.com/kb/HT213845support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comApr 14, 2023, 1:15 AM - https://support.apple.com/kb/HT213844support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comApr 14, 2023, 1:15 AM - https://support.apple.com/kb/HT213843support.apple.com
No excerpt available.
Vendor Advisorysupport.apple.comApr 14, 2023, 1:15 AM - https://security.netapp.com/advisory/ntap-20230517-0009/security.netapp.com
No excerpt available.
Exploitsecurity.netapp.comApr 14, 2023, 1:15 AM - https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgApr 14, 2023, 1:15 AM No excerpt available.
Vendor Advisorylists.debian.orgApr 14, 2023, 1:15 AM- http://www.openwall.com/lists/oss-security/2023/04/19/11www.openwall.com
No excerpt available.
Exploitwww.openwall.comApr 14, 2023, 1:15 AM - http://www.openwall.com/lists/oss-security/2023/04/19/10www.openwall.com
No excerpt available.
Exploitwww.openwall.comApr 14, 2023, 1:15 AM - http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56ncurses.scripts.mit.edu
No excerpt available.
referencencurses.scripts.mit.eduApr 14, 2023, 1:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2020-19190CVSS 6.5 · Medium
Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
- CVE-2020-19189CVSS 6.5 · Medium
Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
- CVE-2020-19188CVSS 6.5 · Medium
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
- CVE-2020-19187CVSS 6.5 · Medium
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
- CVE-2020-19186CVSS 6.5 · Medium
Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
- CVE-2020-19185CVSS 6.5 · Medium
Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.