« List of all CVEs

CVE-2023-29491

Published: 4/14/2023 Last updated: 11/27/2024 Reserved: 4/7/2023

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (6)

bap-llvm clangml conf-mingw-w64-ncurses-i686 conf-mingw-w64-ncurses-x86_64 conf-ncurses curses

Products affected (1)

Product Vendor Version
n/a n/a < 6.1.7601.26321

References (22)