« List of all CVEs

CVE-2023-29491

Published: 4/14/2023 Last updated: 11/4/2025 Reserved: 4/7/2023

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (6)

bap-llvm clangml conf-mingw-w64-ncurses-i686 conf-mingw-w64-ncurses-x86_64 conf-ncurses curses

Products affected (2)

Product Vendor Version
n/a n/a < 14.4
n/a n/a Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1

References (46)