Out-of-bounds write in ncurses - CVE-2020-19189

 

Out-of-bounds write in ncurses - CVE-2020-19189

Published: October 25, 2023


Vulnerability identifier: #VU82358
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-19189
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the postprocess_terminfo() function in tinfo/parse_entry. A local user can run a specially crafted command to trigger an out-of-bounds write and perform a denial of service (DoS) attack.


Affected software

ncurses
RecoverPoint for Virtual Machines
SmartFabric OS10
IBM Sterling Order Management
macOS
Ubuntu
lib32ncursesw5 (Ubuntu package)
ncurses-bin (Ubuntu package)
libx32tinfo5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
libtinfo5 (Ubuntu package)
libncursesw5 (Ubuntu package)
libncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
Juniper Cloud Native Router
Junos cRPD

How to mitigate CVE-2020-19189

Install updates from vendor's website.

ncurses - update to 6.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
SmartFabric OS10 - update to 10.5.4.11
macOS - addressed in versions 12.7.2 21G1974, 13.6.3 22G436, 14.2 23C64
lib32ncursesw5 (Ubuntu package) - update to Ubuntu Pro
ncurses-bin (Ubuntu package) - update to Ubuntu Pro
libx32tinfo5 (Ubuntu package) - update to Ubuntu Pro
libx32ncursesw5 (Ubuntu package) - update to Ubuntu Pro
libx32ncurses5 (Ubuntu package) - update to Ubuntu Pro
libtinfo5 (Ubuntu package) - update to Ubuntu Pro
libncursesw5 (Ubuntu package) - update to Ubuntu Pro
libncurses5 (Ubuntu package) - update to Ubuntu Pro
lib64tinfo5 (Ubuntu package) - update to Ubuntu Pro
lib64ncurses5 (Ubuntu package) - update to Ubuntu Pro
lib32tinfo5 (Ubuntu package) - update to Ubuntu Pro
lib32ncurses5 (Ubuntu package) - update to Ubuntu Pro
IBM Sterling Order Management - update to 10.0.2403.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins