Out-of-bounds write in ncurses - CVE-2020-19188

 

Out-of-bounds write in ncurses - CVE-2020-19188

Published: December 11, 2023


Vulnerability identifier: #VU84082
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-19188
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error within the fmt_entry() function in progs/dump_entry.c. A remote attacker can send a specially crafted command to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

ncurses
webMethods Managed File Transfer
IBM Sterling Order Management
macOS
Juniper Cloud Native Router
Junos cRPD

How to mitigate CVE-2020-19188

Install updates from vendor's website.

ncurses - update to 6.2
macOS - addressed in versions 12.7.2 21G1974, 13.6.3 22G436, 14.2 23C64
IBM Sterling Order Management - update to 10.0.2403.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins