Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 698210 (CVE-2019-17594, CVE-2019-17595) - <sys-libs/ncurses-6.2: multiple vulnerabilities (CVE-2019-{17594,17595})
Summary: <sys-libs/ncurses-6.2: multiple vulnerabilities (CVE-2019-{17594,17595})
Status: IN_PROGRESS
Alias: CVE-2019-17594, CVE-2019-17595
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A3 [stable cve]
Keywords: CC-ARCHES
Depends on:
Blocks:
 
Reported: 2019-10-21 17:15 UTC by lperkins
Modified: 2020-05-11 16:50 UTC (History)
3 users (show)

See Also:
Package list:
=sys-libs/ncurses-6.2-r1
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description lperkins 2019-10-21 17:15:36 UTC
sys-libs/ncurses prior to 6.1-20191012 has security vulnerabilities.  It would be good to get an updated version available in the tree.

Reproducible: Always
Comment 1 Sam James (sec padawan) 2020-03-01 03:51:44 UTC
There is an additional bug CVE-2019-17594:
"There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012."
Comment 2 Sam James (sec padawan) 2020-05-05 22:57:21 UTC
@maintainer(s), please advise if ready for stabilisation, or call yourself
Comment 3 Agostino Sarubbo gentoo-dev 2020-05-06 14:23:40 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2020-05-08 17:12:08 UTC
ppc stable
Comment 5 Agostino Sarubbo gentoo-dev 2020-05-08 17:13:55 UTC
s390 stable
Comment 6 Agostino Sarubbo gentoo-dev 2020-05-08 17:15:21 UTC
sparc stable
Comment 7 Agostino Sarubbo gentoo-dev 2020-05-09 07:43:41 UTC
arm stable
Comment 8 Agostino Sarubbo gentoo-dev 2020-05-09 07:46:58 UTC
ppc64 stable
Comment 9 Sergei Trofimovich gentoo-dev 2020-05-10 08:29:53 UTC
hppa stable
Comment 10 Agostino Sarubbo gentoo-dev 2020-05-11 16:50:02 UTC
x86 stable