Stack-based buffer overflow in ncurses - CVE-2017-10684
Published: April 20, 2018 / Updated: April 23, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the fmt_entry function of ncurses due to stack-based buffer overflow when handling malicious input. A remote unauthenticated attacker can send a request that submits malicious input, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
VMware Tanzu Application Service for VMs
Isolation Segment
Gentoo Linux
SUSE Linux
Ubuntu
Tanzu Greenplum for Kubernetes
StackRox
VMware Tanzu Operations Manager
ncurses (Alpine package)
lib32tinfo5 (Ubuntu package)
libtinfo5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
ncurses-bin (Ubuntu package)
lib64ncurses5 (Ubuntu package)
libncurses5 (Ubuntu package)
libncursesw5 (Ubuntu package)
ncurses-base (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libx32tinfo5 (Ubuntu package)
ncurses-term (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
How to mitigate CVE-2017-10684
StackRox - update to 3.71.0 rc.1
ncurses (Alpine package) - addressed in versions 6.0-r7, 6.0-r8
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
lib32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libtinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-bin (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-base (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-term (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
External References
Related Security Bulletins
- Remote code execution in ncurses
- openSUSE update for ncurses
- openSUSE update for ncurses
- openSUSE update for ncurses
- Gentoo update for ncurses
- Stack-based buffer overflow in ncurses (Alpine package)
- Ubuntu update for ncurses
- Multiple vulnerabilities in StackRox
- VMware Tanzu products update for ncurses