NULL pointer dereference in ncurses - CVE-2023-45918

 

NULL pointer dereference in ncurses - CVE-2023-45918

Published: June 18, 2024


Vulnerability identifier: #VU92195
CSH Severity: Medium
CVSS v4 BT: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-45918
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in tgetstr in tinfo/lib_termcap.c. A remote attacker can trick the victim to open a specially crafted file with the affected application and perform a denial of service (DoS) attack.


Affected software

ncurses
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
Oracle Solaris
Amazon Linux AMI
openEuler
Dell Data Protection Central
DataStax Hyper-Converged Database
PowerProtect DP Series Appliance (IDPA)
Red Hat OpenShift Container Platform
ncurses
ncurses-libs
ncurses-debuginfo
ncurses-devel
ncurses-help
ncurses-debugsource
ncurses-base

How to mitigate CVE-2023-45918

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
Oracle Solaris - update to 11.4 SRU 71
DataStax Hyper-Converged Database - update to 1.2.5
Red Hat OpenShift Container Platform - update to 4.16.7
Dell Secure Connect Gateway - update to 5.24.00.14
ncurses - update to 6.2-4.20200222
ncurses - update to 6.2-6
ncurses-libs - update to 6.2-6
ncurses-debuginfo - update to 6.2-6
ncurses-devel - update to 6.2-6
ncurses-help - update to 6.2-6
ncurses-debugsource - update to 6.2-6
ncurses-base - update to 6.2-6

External References

Related Security Bulletins