Improper input validation in ncurses - CVE-2017-13733
Published: April 26, 2018
Vulnerability identifier: #VU12200
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13733
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the fmt_entry function in progs/dump_entry.c due to an illegal address access. A remote attacker can cause the service to crash.
The weakness exists in the fmt_entry function in progs/dump_entry.c due to an illegal address access. A remote attacker can cause the service to crash.
Affected software
ncurses
VMware Tanzu Application Service for VMs
Isolation Segment
Gentoo Linux
SUSE Linux
Ubuntu
Tanzu Greenplum for Kubernetes
Integrated Management Module II (IMM2) for BladeCenter Systems
ncurses (Alpine package)
ncurses-base (Ubuntu package)
ncurses-term (Ubuntu package)
libx32tinfo5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libncursesw5 (Ubuntu package)
libncurses5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
ncurses-bin (Ubuntu package)
lib32ncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
libtinfo5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
Flex System Integrated Management Module (IMM2)
System x Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
VMware Tanzu Operations Manager
VMware Tanzu Application Service for VMs
Isolation Segment
Gentoo Linux
SUSE Linux
Ubuntu
Tanzu Greenplum for Kubernetes
Integrated Management Module II (IMM2) for BladeCenter Systems
ncurses (Alpine package)
ncurses-base (Ubuntu package)
ncurses-term (Ubuntu package)
libx32tinfo5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libncursesw5 (Ubuntu package)
libncurses5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
ncurses-bin (Ubuntu package)
lib32ncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
libtinfo5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
Flex System Integrated Management Module (IMM2)
System x Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
VMware Tanzu Operations Manager
How to mitigate CVE-2017-13733
Update to version 6.1.
Tanzu Greenplum for Kubernetes - update to 2.0.0
ncurses (Alpine package) - update to 6.0_p20170701-r0
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
ncurses-base (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-term (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-bin (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libtinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses (Alpine package) - update to 6.0_p20170701-r0
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
ncurses-base (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-term (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
ncurses-bin (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib64tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libtinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32tinfo5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
lib32ncursesw5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
libx32ncurses5 (Ubuntu package) - update to 6.0+201602131ubuntu1+esm1
External References
Related Security Bulletins
- Gentoo update for ncurses
- SUSE Linux update for ncurses
- Improper input validation in ncurses (Alpine package)
- Ubuntu update for ncurses
- VMware Tanzu products update for ncurses
- IBM Integrated Management Module II (IMM2) update for Ncurses
- IBM Flex System Chassis Management Module (CMM) update for Ncurses