In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | 288c96aa5b5526cd4a946e84ef85e165857693b5 |