Infinite loop in ncurses - CVE-2017-13728

 

Infinite loop in ncurses - CVE-2017-13728

Published: April 26, 2018


Vulnerability identifier: #VU12195
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13728
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause Dos condition on the target system.

The weakness exists in the next_char function in comp_scan.c due to an infinite loop. A remote attacker can submit a specially crafted input and cause the service to crash.

Affected software

ncurses
VMware Tanzu Application Service for VMs
Isolation Segment
Gentoo Linux
SUSE Linux
Ubuntu
Tanzu Greenplum for Kubernetes
ncurses (Alpine package)
libncurses5 (Ubuntu package)
ncurses-term (Ubuntu package)
libx32tinfo5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
ncurses-base (Ubuntu package)
libncursesw5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
ncurses-bin (Ubuntu package)
lib32ncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
libtinfo5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
VMware Tanzu Operations Manager

How to mitigate CVE-2017-13728

Update to version 6.1.

Tanzu Greenplum for Kubernetes - update to 2.0.0
ncurses (Alpine package) - update to 6.0_p20170701-r0
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
libncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-term (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-base (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-bin (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libtinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1

External References

Related Security Bulletins