Buffer Over-read in ncurses - CVE-2019-17595
Published: October 15, 2019 / Updated: July 28, 2022
Vulnerability identifier: #VU21793
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17595
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read issue in the "fmt_entry" function in "tinfo/comp_hash.c" in the terminfo library. A remote attacker can trigger a buffer over-read condition and cause a denial of service condition on the target system.Affected software
ncurses
VMware Tanzu Application Service for VMs
Isolation Segment
Ansible Automation Platform
IBM Sterling Connect:Direct for UNIX
IBM Cloud Pak for Business Automation
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
Opensuse
Tanzu Greenplum for Kubernetes
cflinuxfs3
Platform Automation Toolkit
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
HPE Moonshot 1500 Chassis Manager
Cloud Pak for Security (CP4S)
VMware Tanzu Operations Manager
Red Hat OpenShift Serverless
OpenShift Virtualization
ncurses-bin (Ubuntu package)
libncursesw5 (Ubuntu package)
libx32tinfo5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
libtinfo5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
libncurses5 (Ubuntu package)
ncurses (Red Hat package)
libncursesw6 (Ubuntu package)
libncurses6 (Ubuntu package)
libtinfo6 (Ubuntu package)
lib64ncursesw6 (Ubuntu package)
lib64ncurses6 (Ubuntu package)
lib64tinfo6 (Ubuntu package)
lib32ncursesw6 (Ubuntu package)
lib32ncurses6 (Ubuntu package)
lib32tinfo6 (Ubuntu package)
VMware Tanzu Application Service for VMs
Isolation Segment
Ansible Automation Platform
IBM Sterling Connect:Direct for UNIX
IBM Cloud Pak for Business Automation
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
Opensuse
Tanzu Greenplum for Kubernetes
cflinuxfs3
Platform Automation Toolkit
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
HPE Moonshot 1500 Chassis Manager
Cloud Pak for Security (CP4S)
VMware Tanzu Operations Manager
Red Hat OpenShift Serverless
OpenShift Virtualization
ncurses-bin (Ubuntu package)
libncursesw5 (Ubuntu package)
libx32tinfo5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
libtinfo5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
libncurses5 (Ubuntu package)
ncurses (Red Hat package)
libncursesw6 (Ubuntu package)
libncurses6 (Ubuntu package)
libtinfo6 (Ubuntu package)
lib64ncursesw6 (Ubuntu package)
lib64ncurses6 (Ubuntu package)
lib64tinfo6 (Ubuntu package)
lib32ncursesw6 (Ubuntu package)
lib32ncurses6 (Ubuntu package)
lib32tinfo6 (Ubuntu package)
How to mitigate CVE-2019-17595
Install updates from vendor's website.
ncurses - update to 6.1-20191012
Tanzu Greenplum for Kubernetes - update to 2.0.0
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.3, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
VMware Tanzu Operations Manager - addressed in versions 2.9.41, 2.10.44, 2.10.59, 3.0.11
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
IBM Sterling Connect:Direct for UNIX - update to 6.2.0.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
ncurses-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 6.0+201602131ubuntu1+esm2, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libx32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libtinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.0+201602131ubuntu1+esm2, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.0+201602131ubuntu1+esm2, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
cflinuxfs3 - update to 0.367.0
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
OpenShift Virtualization - update to 4.11.0
ncurses (Red Hat package) - update to 6.1-9.20180224.el8
libncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libtinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
Red Hat OpenStack - update to 16.2
Tanzu Greenplum for Kubernetes - update to 2.0.0
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.3, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
VMware Tanzu Operations Manager - addressed in versions 2.9.41, 2.10.44, 2.10.59, 3.0.11
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
IBM Sterling Connect:Direct for UNIX - update to 6.2.0.4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
ncurses-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 6.0+201602131ubuntu1+esm2, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libx32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libtinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.0+201602131ubuntu1+esm2, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.0+201602131ubuntu1+esm2, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
cflinuxfs3 - update to 0.367.0
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
OpenShift Virtualization - update to 4.11.0
ncurses (Red Hat package) - update to 6.1-9.20180224.el8
libncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libtinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
Red Hat OpenStack - update to 16.2
External References
Related Security Bulletins
- Multiple vulnerabilities in ncurses
- OpenSUSE Linux update for ncurses
- OpenSUSE Linux update for ncurses
- Gentoo update for ncurses
- Red Hat Enterprise Linux 8 update for ncurses
- Ubuntu update for ncurses
- VMware Tanzu products update for ncurses
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in IBM Sterling Connect:Direct for UNIX Certified Container
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in OpenShift Virtualization
- Ubuntu update for ncurses
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- VMware Tanzu products update for ncurses
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2