Stack-based buffer overflow in the ncwriteentry function in tinfo/writeentry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.
{
"binaries": [
{
"binary_name": "lib32ncurses5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "lib32ncurses5-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "lib32ncursesw5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "lib32ncursesw5-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "lib32tinfo-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "lib32tinfo5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "lib64ncurses5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "lib64ncurses5-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "lib64tinfo5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libncurses5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libncurses5-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libncursesw5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libncursesw5-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libtinfo-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libtinfo5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libx32ncurses5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libx32ncurses5-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libx32ncursesw5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libx32ncursesw5-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libx32tinfo-dev",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "libx32tinfo5",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "ncurses-base",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "ncurses-bin",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "ncurses-examples",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
},
{
"binary_name": "ncurses-term",
"binary_version": "5.9+20140118-1ubuntu1+esm2"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_name": "lib32ncurses5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "lib32ncurses5-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "lib32ncursesw5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "lib32ncursesw5-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "lib32tinfo-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "lib32tinfo5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "lib64ncurses5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "lib64ncurses5-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "lib64tinfo5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libncurses5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libncurses5-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libncursesw5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libncursesw5-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libtinfo-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libtinfo5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libx32ncurses5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libx32ncurses5-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libx32ncursesw5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libx32ncursesw5-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libx32tinfo-dev",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "libx32tinfo5",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "ncurses-base",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "ncurses-bin",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "ncurses-examples",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
},
{
"binary_name": "ncurses-term",
"binary_version": "6.0+20160213-1ubuntu1+esm2"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}