CVE-2017-10684: Buffer Overflow
Published Jun 29, 2017
·Updated
In ncurses 6.0, there is a stack-based buffer overflow in the fmtentry function. A crafted input will lead to a remote arbitrary code execution attack.
Affected Software
2 affected components
GNU ncurses=6.0
invisible-island Ncurses=6.0
Event History
Jun 29, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-10684?
CVE-2017-10684 has a high severity rating due to its potential for remote arbitrary code execution.
2
How do I fix CVE-2017-10684?
To fix CVE-2017-10684, upgrading to a patched version of ncurses beyond 6.0 is recommended.
3
What impact does CVE-2017-10684 have on systems?
CVE-2017-10684 can lead to a stack-based buffer overflow which can be exploited for remote code execution.
4
Which versions of ncurses are affected by CVE-2017-10684?
CVE-2017-10684 affects ncurses version 6.0 only.
5
Is there a known exploit for CVE-2017-10684?
Yes, there are reports of exploits that can leverage CVE-2017-10684 to execute arbitrary code remotely.