Use of externally-controlled format string in ncurses - CVE-2017-10685

 

Use of externally-controlled format string in ncurses - CVE-2017-10685

Published: April 26, 2018


Vulnerability identifier: #VU12190
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-10685
CWE-ID: CWE-134
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists in the fmt_entry function due to use of externally-controlled format string. A remote attacker can submit a specially crafted input and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

ncurses
VMware Tanzu Application Service for VMs
Isolation Segment
Gentoo Linux
SUSE Linux
Ubuntu
Tanzu Greenplum for Kubernetes
StackRox
VMware Tanzu Operations Manager
ncurses (Alpine package)
lib32tinfo5 (Ubuntu package)
libtinfo5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
ncurses-bin (Ubuntu package)
lib64ncurses5 (Ubuntu package)
libncurses5 (Ubuntu package)
libncursesw5 (Ubuntu package)
ncurses-base (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libx32tinfo5 (Ubuntu package)
ncurses-term (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)

How to mitigate CVE-2017-10685

Update to version 6.1.

Tanzu Greenplum for Kubernetes - update to 2.0.0
StackRox - update to 3.71.0 rc.1
ncurses (Alpine package) - addressed in versions 6.0-r7, 6.0-r8
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
lib32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libtinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-bin (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-base (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-term (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1

External References

Related Security Bulletins