Out-of-bounds write in ncurses - CVE-2020-19185
Published: December 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error within the one_one_mapping() function in progs/dump_entry.c. A remote attacker can send a specially crafted command to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
macOS
IBM Sterling Order Management
Juniper Cloud Native Router
Junos cRPD
How to mitigate CVE-2020-19185
macOS - addressed in versions 12.7.2 21G1974, 13.6.3 22G436, 14.2 23C64
IBM Sterling Order Management - update to 10.0.2403.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- Multiple vulnerabilities in ncurses
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Sterling Order Management