Summary: | <sys-libs/ncurses-6.1: Multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Aleksandr Wagner (Kivak) <alwag> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | base-system, sudormrfhalt |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | A1 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 639706, 648114 | ||
Bug Blocks: |
Description
Aleksandr Wagner (Kivak)
2017-07-21 08:31:59 UTC
CVE-2017-10685 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10685): In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack. This issue was resolved and addressed in GLSA 201804-13 at https://security.gentoo.org/glsa/201804-13 by GLSA coordinator Aaron Bauman (b-man). |