Heap-based buffer overflow in ncurses - CVE-2019-17594

 

Heap-based buffer overflow in ncurses - CVE-2019-17594

Published: October 15, 2019 / Updated: July 28, 2022


Vulnerability identifier: #VU21792
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17594
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the "_nc_find_entry" function in "tinfo/comp_hash.c" in the terminfo library. A remote attacker can trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

ncurses
VMware Tanzu Application Service for VMs
Isolation Segment
Ansible Automation Platform
IBM Sterling Connect:Direct for UNIX
IBM Cloud Pak for Business Automation
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
Opensuse
Tanzu Greenplum for Kubernetes
cflinuxfs3
Platform Automation Toolkit
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
HPE Moonshot 1500 Chassis Manager
Cloud Pak for Security (CP4S)
VMware Tanzu Operations Manager
Red Hat OpenShift Serverless
OpenShift Virtualization
ncurses-bin (Ubuntu package)
libncursesw5 (Ubuntu package)
libx32tinfo5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
libtinfo5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
libncurses5 (Ubuntu package)
ncurses (Red Hat package)
libncursesw6 (Ubuntu package)
libncurses6 (Ubuntu package)
libtinfo6 (Ubuntu package)
lib64ncursesw6 (Ubuntu package)
lib64ncurses6 (Ubuntu package)
lib64tinfo6 (Ubuntu package)
lib32ncursesw6 (Ubuntu package)
lib32ncurses6 (Ubuntu package)
lib32tinfo6 (Ubuntu package)

How to mitigate CVE-2019-17594

Install updates from vendor's website.

ncurses - update to 6.1-20191012
Tanzu Greenplum for Kubernetes - update to 2.0.0
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.3, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
VMware Tanzu Operations Manager - addressed in versions 2.9.41, 2.10.44, 2.10.59, 3.0.11
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
IBM Sterling Connect:Direct for UNIX - update to 6.2.0.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
ncurses-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 6.0+201602131ubuntu1+esm2, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libx32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libtinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.0+201602131ubuntu1+esm2, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.0+201602131ubuntu1+esm2, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
cflinuxfs3 - update to 0.367.0
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
OpenShift Virtualization - update to 4.11.0
ncurses (Red Hat package) - update to 6.1-9.20180224.el8
libncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libtinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins