CVE-2017-16879 PUBLISHED

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.

EPSS 0.44% · 62.9th percentile

Risk Scores

EPSS Score
0.44%
62.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSncurses0, 5.9+20130608-1ubuntu1, 5.9+20131221-1ubuntu1
Ubuntu:Pro:16.04:LTSncurses0, 5.9+20150516-2ubuntu1, 6.0+20151024-2ubuntu1

Timeline

References

Open in Interactive Console →