Buffer overflow in ncurses - CVE-2023-29491
Published: April 14, 2023
Vulnerability identifier: #VU75141
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29491
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing malformed data in a terminfo database file. A local user can trigger memory corruption and execute arbitrary code on the target system.
Affected software
ncurses
Migration Toolkit for Runtimes
VMware Tanzu Application Service for VMs
Isolation Segment
Fence Agents Remediation Operator
Run Once Duration Override Operator for Red Hat OpenShift
Red Hat OpenShift Builds
Data Lakehouse
Service Telemetry Framework
OpenShift Pipelines
cert-manager Operator for Red Hat OpenShift
Cryostat
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Binding Support Function
Submariner
Multicluster GlobalHub
IBM MQ Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
IBM Cloud Pak for Data Scheduling
IBM Security Verify Governance
IBM Automation Decision Services
Juniper Cloud Native Router
Gentoo Linux
Amazon Linux AMI
Oracle Linux
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Solaris
Ubuntu
openEuler
Fedora
macOS
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM Business Automation Manager Open Editions
SmartFabric OS10
webMethods Managed File Transfer
Robotic Process Automation for Cloud Pak
cflinuxfs3
ObjectScale
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
Storage Ceph
IBM supplied MQ Advanced container images
Total Storage Service Console (TSSC) / TS4500 IMC
IBM Sterling Order Management
Dell PowerProtect Cyber Recovery
API Portal
Node Health Check Operator
Self Node Remediation Operator
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
Node Maintenance Operator
OpenShift Container Platform for Windows Containers
VMware Tanzu Operations Manager
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
Junos cRPD
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libncursesw5 (Ubuntu package)
libncurses5 (Ubuntu package)
libtinfo5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libx32tinfo5 (Ubuntu package)
ncurses-bin (Ubuntu package)
ncurses
ncurses (Red Hat package)
ncurses-term
ncurses-base
ncurses-libs
ncurses-devel
ncurses-compat-libs
ncurses-c++-libs
lib32ncurses6 (Ubuntu package)
lib64tinfo6 (Ubuntu package)
libtinfo6 (Ubuntu package)
lib32tinfo6 (Ubuntu package)
lib64ncurses6 (Ubuntu package)
lib32ncursesw6 (Ubuntu package)
libncursesw6 (Ubuntu package)
lib64ncursesw6 (Ubuntu package)
libncurses6 (Ubuntu package)
ncurses-debuginfo
ncurses-help
ncurses-debugsource
ncurses-doc
ncurses-static
Oracle Communications Cloud Native Core Policy
Red Hat OpenShift GitOps
RecoverPoint for VMs
Red Hat Ceph Storage
Dell EMC VxRail Appliance
Dell EMC NetWorker vProxy
Migration Toolkit for Runtimes
VMware Tanzu Application Service for VMs
Isolation Segment
Fence Agents Remediation Operator
Run Once Duration Override Operator for Red Hat OpenShift
Red Hat OpenShift Builds
Data Lakehouse
Service Telemetry Framework
OpenShift Pipelines
cert-manager Operator for Red Hat OpenShift
Cryostat
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
Oracle Communications Cloud Native Core Binding Support Function
Submariner
Multicluster GlobalHub
IBM MQ Operator
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
IBM Cloud Pak for Data Scheduling
IBM Security Verify Governance
IBM Automation Decision Services
Juniper Cloud Native Router
Gentoo Linux
Amazon Linux AMI
Oracle Linux
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Solaris
Ubuntu
openEuler
Fedora
macOS
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
IBM Business Automation Manager Open Editions
SmartFabric OS10
webMethods Managed File Transfer
Robotic Process Automation for Cloud Pak
cflinuxfs3
ObjectScale
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
Storage Ceph
IBM supplied MQ Advanced container images
Total Storage Service Console (TSSC) / TS4500 IMC
IBM Sterling Order Management
Dell PowerProtect Cyber Recovery
API Portal
Node Health Check Operator
Self Node Remediation Operator
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
Node Maintenance Operator
OpenShift Container Platform for Windows Containers
VMware Tanzu Operations Manager
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
Junos cRPD
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libncursesw5 (Ubuntu package)
libncurses5 (Ubuntu package)
libtinfo5 (Ubuntu package)
libx32ncurses5 (Ubuntu package)
lib32ncursesw5 (Ubuntu package)
lib32tinfo5 (Ubuntu package)
lib32ncurses5 (Ubuntu package)
lib64tinfo5 (Ubuntu package)
lib64ncurses5 (Ubuntu package)
libx32ncursesw5 (Ubuntu package)
libx32tinfo5 (Ubuntu package)
ncurses-bin (Ubuntu package)
ncurses
ncurses (Red Hat package)
ncurses-term
ncurses-base
ncurses-libs
ncurses-devel
ncurses-compat-libs
ncurses-c++-libs
lib32ncurses6 (Ubuntu package)
lib64tinfo6 (Ubuntu package)
libtinfo6 (Ubuntu package)
lib32tinfo6 (Ubuntu package)
lib64ncurses6 (Ubuntu package)
lib32ncursesw6 (Ubuntu package)
libncursesw6 (Ubuntu package)
lib64ncursesw6 (Ubuntu package)
libncurses6 (Ubuntu package)
ncurses-debuginfo
ncurses-help
ncurses-debugsource
ncurses-doc
ncurses-static
Oracle Communications Cloud Native Core Policy
Red Hat OpenShift GitOps
RecoverPoint for VMs
Red Hat Ceph Storage
Dell EMC VxRail Appliance
Dell EMC NetWorker vProxy
How to mitigate CVE-2023-29491
Install updates from vendor's website.
ncurses - update to 6.4 20230408
Migration Toolkit for Runtimes - update to 1.2.1
Dell EMC PowerProtect Data Protection - update to 2.7.8
API Portal - update to August 2023
Fence Agents Remediation Operator - update to 0.2.1
Node Health Check Operator - addressed in versions 0.4.1, 0.6.1
Self Node Remediation Operator - addressed in versions 0.5.1, 0.7.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Red Hat OpenShift Serverless - addressed in versions 1.30.1, 1.30.2
Red Hat OpenShift Builds - update to 1.0.1
Data Lakehouse - update to 1.1.0.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - addressed in versions 1.1.3, 1.2.0
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.13, 1.8.0
OpenShift Pipelines - addressed in versions 1.10.6, 1.11.2, 1.12.1
cert-manager Operator for Red Hat OpenShift - addressed in versions 1.11.5, 1.12.1
Multicluster Engine for Kubernetes - addressed in versions 2.1.9, 2.2.9, 2.3.2, 2.3.3, 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4
OpenShift Service Mesh - addressed in versions 2.2.11, 2.3.8, 2.4.4, 2.4.8, 2.5.2
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.8, 2.7.9, 2.8.2, 2.10.5, 2.10.8, 2.11.4, 2.11.7, 2.12.0, 2.12.1, 2.12.3
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.0.5, 4.1.4
OpenShift Virtualization - addressed in versions 4.11.7, 4.13.6, 4.14.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.24, 4.14.0, 4.14.4, 4.16.15, 4.16.44, 4.17.0
Node Maintenance Operator - addressed in versions 5.0.1, 5.2.1
OpenShift Logging - addressed in versions 5.5.17, 5.6.12, 5.7.7, 5.8.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Red Hat Migration Toolkit for Applications - addressed in versions 6.1.4, 6.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.002
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4 SP1
IBM Business Automation Manager Open Editions - update to 8.0.4 IF001
OpenShift Container Platform for Windows Containers - addressed in versions 9.0.1, 10.15.0
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
Red Hat OpenStack - update to 16.2.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
libncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libtinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libx32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
ncurses-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
Submariner - update to 0.18.5
cflinuxfs3 - update to 0.367.0
Multicluster GlobalHub - update to 1.2.1
ObjectScale - update to 1.4.0
Network Observability plugin for the Openshift Console - update to 1.5.0
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
IBM MQ Operator - addressed in versions 2.0.16, 2.4.4
VMware Tanzu Operations Manager - addressed in versions 2.10.59, 3.0.11
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Enterprise SONiC - update to 4.2.1
IBM Cloud Pak for Watson AIOps - update to 4.4.0
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
IBM Cloud Pak for Data Scheduling - update to 4.8.0
ncurses - addressed in versions 5.7-4.20090207.15, 6.2-4.20200222
RecoverPoint for VMs - update to 6.0.SP1.P1
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1z3
ncurses (Red Hat package) - addressed in versions 6.1-9.20180224.el8_6.1, 6.1-9.20180224.el8_8.1, 6.2-8.20210508.el9_2.1, 6.2-10.20210508.el9
ncurses-term - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-base - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-libs - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-devel - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-compat-libs - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-c++-libs - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
lib32ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libtinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
ncurses-base - update to 6.2-4
ncurses-debuginfo - update to 6.2-4
ncurses-devel - update to 6.2-4
ncurses-libs - update to 6.2-4
ncurses-help - update to 6.2-4
ncurses-debugsource - update to 6.2-4
ncurses - update to 6.2-4
ncurses-doc - update to 6.4-3.20240127
ncurses-static - update to 6.4-3.20240127
ncurses - update to 6.4-7.20230520.fc38
Dell EMC VxRail Appliance - update to 8.0.101
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.11-r1, 9.3.3.2-r1
Total Storage Service Console (TSSC) / TS4500 IMC - addressed in versions 9.4.26, 9.5.8
IBM Security Verify Governance - update to 10.0.2.0.4
IBM Sterling Order Management - update to 10.0.2403.1
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.5 22G74
Dell EMC NetWorker vProxy - addressed in versions 19.8.0.3, 19.9.0.2
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
IBM Automation Decision Services - update to 23.0.1 IF003
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
Migration Toolkit for Runtimes - update to 1.2.1
Dell EMC PowerProtect Data Protection - update to 2.7.8
API Portal - update to August 2023
Fence Agents Remediation Operator - update to 0.2.1
Node Health Check Operator - addressed in versions 0.4.1, 0.6.1
Self Node Remediation Operator - addressed in versions 0.5.1, 0.7.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.0.1
Red Hat OpenShift Serverless - addressed in versions 1.30.1, 1.30.2
Red Hat OpenShift Builds - update to 1.0.1
Data Lakehouse - update to 1.1.0.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - addressed in versions 1.1.3, 1.2.0
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.13, 1.8.0
OpenShift Pipelines - addressed in versions 1.10.6, 1.11.2, 1.12.1
cert-manager Operator for Red Hat OpenShift - addressed in versions 1.11.5, 1.12.1
Multicluster Engine for Kubernetes - addressed in versions 2.1.9, 2.2.9, 2.3.2, 2.3.3, 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4
OpenShift Service Mesh - addressed in versions 2.2.11, 2.3.8, 2.4.4, 2.4.8, 2.5.2
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.8, 2.7.9, 2.8.2, 2.10.5, 2.10.8, 2.11.4, 2.11.7, 2.12.0, 2.12.1, 2.12.3
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.0.5, 4.1.4
OpenShift Virtualization - addressed in versions 4.11.7, 4.13.6, 4.14.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.24, 4.14.0, 4.14.4, 4.16.15, 4.16.44, 4.17.0
Node Maintenance Operator - addressed in versions 5.0.1, 5.2.1
OpenShift Logging - addressed in versions 5.5.17, 5.6.12, 5.7.7, 5.8.1
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Red Hat Migration Toolkit for Applications - addressed in versions 6.1.4, 6.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.002
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.4 SP1
IBM Business Automation Manager Open Editions - update to 8.0.4 IF001
OpenShift Container Platform for Windows Containers - addressed in versions 9.0.1, 10.15.0
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
Red Hat OpenStack - update to 16.2.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
libncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libtinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libx32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib32ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
lib64ncurses5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32ncursesw5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
libx32tinfo5 (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1
ncurses-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 6.1-1ubuntu1.18.04.1, 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
Submariner - update to 0.18.5
cflinuxfs3 - update to 0.367.0
Multicluster GlobalHub - update to 1.2.1
ObjectScale - update to 1.4.0
Network Observability plugin for the Openshift Console - update to 1.5.0
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
IBM MQ Operator - addressed in versions 2.0.16, 2.4.4
VMware Tanzu Operations Manager - addressed in versions 2.10.59, 3.0.11
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
Enterprise SONiC - update to 4.2.1
IBM Cloud Pak for Watson AIOps - update to 4.4.0
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
IBM Cloud Pak for Data Scheduling - update to 4.8.0
ncurses - addressed in versions 5.7-4.20090207.15, 6.2-4.20200222
RecoverPoint for VMs - update to 6.0.SP1.P1
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1z3
ncurses (Red Hat package) - addressed in versions 6.1-9.20180224.el8_6.1, 6.1-9.20180224.el8_8.1, 6.2-8.20210508.el9_2.1, 6.2-10.20210508.el9
ncurses-term - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-base - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-libs - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-devel - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-compat-libs - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
ncurses-c++-libs - addressed in versions 6.1-10.20180224.0.1, 6.4-3.20240127
lib32ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libtinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32tinfo6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib32ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
lib64ncursesw6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
libncurses6 (Ubuntu package) - addressed in versions 6.2-0ubuntu2.1, 6.3-2ubuntu0.1, 6.3+20220423-2ubuntu0.1, 6.4-2ubuntu0.1
ncurses-base - update to 6.2-4
ncurses-debuginfo - update to 6.2-4
ncurses-devel - update to 6.2-4
ncurses-libs - update to 6.2-4
ncurses-help - update to 6.2-4
ncurses-debugsource - update to 6.2-4
ncurses - update to 6.2-4
ncurses-doc - update to 6.4-3.20240127
ncurses-static - update to 6.4-3.20240127
ncurses - update to 6.4-7.20230520.fc38
Dell EMC VxRail Appliance - update to 8.0.101
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.11-r1, 9.3.3.2-r1
Total Storage Service Console (TSSC) / TS4500 IMC - addressed in versions 9.4.26, 9.5.8
IBM Security Verify Governance - update to 10.0.2.0.4
IBM Sterling Order Management - update to 10.0.2403.1
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.5 22G74
Dell EMC NetWorker vProxy - addressed in versions 19.8.0.3, 19.9.0.2
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
IBM Automation Decision Services - update to 23.0.1 IF003
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- Memory corruption in ncurses
- Ubuntu update for ncurses
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- VMware Tanzu products update for ncurses
- Amazon Linux AMI update for ncurses
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Big Sur
- Red Hat Enterprise Linux 8 update for ncurses
- Axway API Portal update for third-party components
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.8
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.1
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh for 2.4
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.2
- Multiple vulnerabilities in Logging Subsystem 5.6 for Red Hat OpenShift
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat Self Node Remediation Operator 0.5
- Multiple vulnerabilities in Red Hat Self Node Remediation Operator 0.7
- Multiple vulnerabilities in Red Hat Node Maintenance Operator 5.2
- Multiple vulnerabilities in Red Hat Node Maintenance Operator 5.0
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.0
- Multiple vulnerabilities in Logging Subsystem 5.5 for Red Hat OpenShift
- Multiple vulnerabilities in Cryostat 2 on RHEL 8
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.12
- Multiple vulnerabilities in Red Hat Process Automation Manager 7.13
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.1
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift 1.2
- Multiple vulnerabilities in Red Hat OpenShift Virtualization release 4.11
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.7
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Red Hat Enterprise Linux 9 update for ncurses
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift 1.1
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1 on RHEL 8
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Node Health Check Operator 0.6
- Multiple vulnerabilities in Node Health Check Operator 0.4
- Multiple vulnerabilities in Fence Agents Remediation Operator
- Multiple vulnerabilities in Migration Toolkit for Applications 6.1
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.11
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 9.2 Extended Update Support update for ncurses
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift 1.12
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift 1.11
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple security vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Dell NetWorker vProxy
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- IBM Cloud Pak for Data Scheduling update for ncurses
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.10
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Multiple vulnerabilities in Red Hat Ceph Storage 6.1
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Fedora 38 update for ncurses
- Buffer overflow in IBM Storage Ceph
- Red Hat Enterprise Linux 8.6 Extended Update Support update for ncurses
- Multiple vulnerabilities in Red Hat Network Observability
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 10.15
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- openEuler update for ncurses
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 9.0
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Buffer overflow in IBM Total Storage Service Console (TSSC) / TS4500 IMC
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Dell SmartFabric OS10
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in Dell ObjectScale
- Gentoo update for ncurses
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.5
- Multiple vulnerabilities in Multicluster GlobalHub 1.2
- Amazon Linux AMI update for ncurses
- Anolis OS update for ncurses
- PowerProtect Data Protection software update for third-party components
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Anolis OS update for ncurses
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Submariner 0.18
- Multiple vulnerabilities in Meinberg LANTIME firmware (August 2023)
- Dell RecoverPoint for Virtual Machines update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16