Out-of-bounds write in ncurses - CVE-2020-19189
Published: October 25, 2023
Vulnerability identifier: #VU82358
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-19189
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the postprocess_terminfo() function in tinfo/parse_entry. A local user can run a specially crafted command to trigger an out-of-bounds write and perform a denial of service (DoS) attack.
Affected software
ncurses
RecoverPoint for Virtual Machines
SmartFabric OS10
IBM Sterling Order Management
macOS
Ubuntu
lib32ncursesw5 (Ubuntu package)
ncurses-bin (Ubuntu package)
libx32tinfo5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
libtinfo5 (Ubuntu package)
libncursesw5 (Ubuntu package)
libncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
Juniper Cloud Native Router
Junos cRPD
RecoverPoint for Virtual Machines
SmartFabric OS10
IBM Sterling Order Management
macOS
Ubuntu
lib32ncursesw5 (Ubuntu package)
ncurses-bin (Ubuntu package)
libx32tinfo5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
libtinfo5 (Ubuntu package)
libncursesw5 (Ubuntu package)
libncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
Juniper Cloud Native Router
Junos cRPD
How to mitigate CVE-2020-19189
Install updates from vendor's website.
ncurses - update to 6.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
SmartFabric OS10 - update to 10.5.4.11
macOS - addressed in versions 12.7.2 21G1974, 13.6.3 22G436, 14.2 23C64
lib32ncursesw5 (Ubuntu package) - update to Ubuntu Pro
ncurses-bin (Ubuntu package) - update to Ubuntu Pro
libx32tinfo5 (Ubuntu package) - update to Ubuntu Pro
libx32ncursesw5 (Ubuntu package) - update to Ubuntu Pro
libx32ncurses5 (Ubuntu package) - update to Ubuntu Pro
libtinfo5 (Ubuntu package) - update to Ubuntu Pro
libncursesw5 (Ubuntu package) - update to Ubuntu Pro
libncurses5 (Ubuntu package) - update to Ubuntu Pro
lib64tinfo5 (Ubuntu package) - update to Ubuntu Pro
lib64ncurses5 (Ubuntu package) - update to Ubuntu Pro
lib32tinfo5 (Ubuntu package) - update to Ubuntu Pro
lib32ncurses5 (Ubuntu package) - update to Ubuntu Pro
IBM Sterling Order Management - update to 10.0.2403.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
SmartFabric OS10 - update to 10.5.4.11
macOS - addressed in versions 12.7.2 21G1974, 13.6.3 22G436, 14.2 23C64
lib32ncursesw5 (Ubuntu package) - update to Ubuntu Pro
ncurses-bin (Ubuntu package) - update to Ubuntu Pro
libx32tinfo5 (Ubuntu package) - update to Ubuntu Pro
libx32ncursesw5 (Ubuntu package) - update to Ubuntu Pro
libx32ncurses5 (Ubuntu package) - update to Ubuntu Pro
libtinfo5 (Ubuntu package) - update to Ubuntu Pro
libncursesw5 (Ubuntu package) - update to Ubuntu Pro
libncurses5 (Ubuntu package) - update to Ubuntu Pro
lib64tinfo5 (Ubuntu package) - update to Ubuntu Pro
lib64ncurses5 (Ubuntu package) - update to Ubuntu Pro
lib32tinfo5 (Ubuntu package) - update to Ubuntu Pro
lib32ncurses5 (Ubuntu package) - update to Ubuntu Pro
IBM Sterling Order Management - update to 10.0.2403.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- Denial of service in ncurses
- Ubuntu update for ncurses
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in Dell SmartFabric OS10
- Dell RecoverPoint for Virtual Machines update for third-party components