CVE-2017-11112 (https://nvd.nist.gov/vuln/detail/CVE-2017-11112): In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data. CVE-2017-11113 (https://nvd.nist.gov/vuln/detail/CVE-2017-11113): In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data. @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
The patches are available. CVE-2017-11112 patch: https://bugzilla.redhat.com/show_bug.cgi?id=1473306 https://lists.gnu.org/archive/html/bug-ncurses/2017-07/msg00001.html CVE-2017-11113 patch: https://bugzilla.redhat.com/show_bug.cgi?id=1473310 https://lists.gnu.org/archive/html/bug-ncurses/2017-07/msg00001.html
This issue was resolved and addressed in GLSA 201804-13 at https://security.gentoo.org/glsa/201804-13 by GLSA coordinator Aaron Bauman (b-man).