Buffer overflow in ncurses - CVE-2023-29491

 

Buffer overflow in ncurses - CVE-2023-29491

Published: April 14, 2023


Vulnerability identifier: #VU75141
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29491
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing malformed data in a terminfo database file. A local user can trigger memory corruption and execute arbitrary code on the target system.



Affected software

ncurses
Migration Toolkit for Runtimes
VMware Tanzu Application Service for VMs
Isolation Segment
Fence Agents Remediation Operator
Run Once Duration Override Operator for Red Hat OpenShift
Red Hat OpenShift Builds
Data Lakehouse
Service Telemetry Framework
OpenShift Pipelines
cert-manager Operator for Red Hat OpenShift
Cryostat
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Binding Support Function
Submariner
Multicluster GlobalHub
IBM MQ Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
IBM Cloud Pak for Data Scheduling
IBM Security Verify Governance
IBM Automation Decision Services
Juniper Cloud Native Router
Gentoo Linux
Amazon Linux AMI
Oracle Linux
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Solaris
Ubuntu
openEuler
Fedora
macOS
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM Business Automation Manager Open Editions
SmartFabric OS10
webMethods Managed File Transfer
Robotic Process Automation for Cloud Pak
cflinuxfs3
ObjectScale
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
Storage Ceph
IBM supplied MQ Advanced container images
Total Storage Service Console (TSSC) / TS4500 IMC
IBM Sterling Order Management
Dell PowerProtect Cyber Recovery
API Portal
Node Health Check Operator
Self Node Remediation Operator
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
Node Maintenance Operator
OpenShift Container Platform for Windows Containers
VMware Tanzu Operations Manager
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
Junos cRPD
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libncursesw5 (Ubuntu package)
libncurses5 (Ubuntu package)
libtinfo5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libx32tinfo5 (Ubuntu package)
ncurses-bin (Ubuntu package)
ncurses
ncurses (Red Hat package)
ncurses-term
ncurses-base
ncurses-libs
ncurses-devel
ncurses-compat-libs
ncurses-c++-libs
lib32ncurses6 (Ubuntu package)
lib64tinfo6 (Ubuntu package)
libtinfo6 (Ubuntu package)
lib32tinfo6 (Ubuntu package)
lib64ncurses6 (Ubuntu package)
lib32ncursesw6 (Ubuntu package)
libncursesw6 (Ubuntu package)
lib64ncursesw6 (Ubuntu package)
libncurses6 (Ubuntu package)
ncurses-debuginfo
ncurses-help
ncurses-debugsource
ncurses-doc
ncurses-static
Oracle Communications Cloud Native Core Policy
Red Hat OpenShift GitOps
RecoverPoint for VMs
Red Hat Ceph Storage
Dell EMC VxRail Appliance
Dell EMC NetWorker vProxy

How to mitigate CVE-2023-29491

Install updates from vendor's website.

ncurses - update to 6.4 20230408
Migration Toolkit for Runtimes - update to 1.2.1
Dell EMC PowerProtect Data Protection - update to 2.7.8
API Portal - update to August 2023
Fence Agents Remediation Operator - update to 0.2.1
Node Health Check Operator - addressed in versions 0.4.1, 0.6.1
Self Node Remediation Operator - addressed in versions 0.5.1, 0.7.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Red Hat OpenShift Serverless - addressed in versions 1.30.1, 1.30.2
Red Hat OpenShift Builds - update to 1.0.1
Data Lakehouse - update to 1.1.0.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - addressed in versions 1.1.3, 1.2.0
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.13, 1.8.0
OpenShift Pipelines - addressed in versions 1.10.6, 1.11.2, 1.12.1
cert-manager Operator for Red Hat OpenShift - addressed in versions 1.11.5, 1.12.1
Multicluster Engine for Kubernetes - addressed in versions 2.1.9, 2.2.9, 2.3.2, 2.3.3, 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4
OpenShift Service Mesh - addressed in versions 2.2.11, 2.3.8, 2.4.4, 2.4.8, 2.5.2
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.8, 2.7.9, 2.8.2, 2.10.5, 2.10.8, 2.11.4, 2.11.7, 2.12.0, 2.12.1, 2.12.3
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.0.5, 4.1.4
OpenShift Virtualization - addressed in versions 4.11.7, 4.13.6, 4.14.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.24, 4.14.0, 4.14.4, 4.16.15, 4.16.44, 4.17.0
Node Maintenance Operator - addressed in versions 5.0.1, 5.2.1
OpenShift Logging - addressed in versions 5.5.17, 5.6.12, 5.7.7, 5.8.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Red Hat Migration Toolkit for Applications - addressed in versions 6.1.4, 6.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.002
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4 SP1
IBM Business Automation Manager Open Editions - update to 8.0.4 IF001
OpenShift Container Platform for Windows Containers - addressed in versions 9.0.1, 10.15.0
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
Red Hat OpenStack - update to 16.2.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
libncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libtinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libx32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
ncurses-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
Submariner - update to 0.18.5
cflinuxfs3 - update to 0.367.0
Multicluster GlobalHub - update to 1.2.1
ObjectScale - update to 1.4.0
Network Observability plugin for the Openshift Console - update to 1.5.0
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
IBM MQ Operator - addressed in versions 2.0.16, 2.4.4
VMware Tanzu Operations Manager - addressed in versions 2.10.59, 3.0.11
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Enterprise SONiC - update to 4.2.1
IBM Cloud Pak for Watson AIOps - update to 4.4.0
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
IBM Cloud Pak for Data Scheduling - update to 4.8.0
ncurses - addressed in versions 5.7-4.20090207.15, 6.2-4.20200222
RecoverPoint for VMs - update to 6.0.SP1.P1
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1z3
ncurses (Red Hat package) - addressed in versions 6.1-9.20180224.el8_6.1, 6.1-9.20180224.el8_8.1, 6.2-8.20210508.el9_2.1, 6.2-10.20210508.el9
ncurses-term - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-base - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-libs - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-devel - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-compat-libs - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-c++-libs - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
lib32ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libtinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
ncurses-base - update to 6.2-4
ncurses-debuginfo - update to 6.2-4
ncurses-devel - update to 6.2-4
ncurses-libs - update to 6.2-4
ncurses-help - update to 6.2-4
ncurses-debugsource - update to 6.2-4
ncurses - update to 6.2-4
ncurses-doc - update to 6.4-3.20240127
ncurses-static - update to 6.4-3.20240127
ncurses - update to 6.4-7.20230520.fc38
Dell EMC VxRail Appliance - update to 8.0.101
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.11-r1, 9.3.3.2-r1
Total Storage Service Console (TSSC) / TS4500 IMC - addressed in versions 9.4.26, 9.5.8
IBM Security Verify Governance - update to 10.0.2.0.4
IBM Sterling Order Management - update to 10.0.2403.1
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.5 22G74
Dell EMC NetWorker vProxy - addressed in versions 19.8.0.3, 19.9.0.2
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
IBM Automation Decision Services - update to 23.0.1 IF003
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins