CVE-2017-10685: Critical severity GNU ncurses vulnerability
Published Jun 29, 2017
·Updated
In ncurses 6.0, there is a format string vulnerability in the fmtentry function. A crafted input will lead to a remote arbitrary code execution attack.
Affected Software
2 affected components
GNU ncurses=6.0
invisible-island Ncurses=6.0
Event History
Jun 29, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-10685?
CVE-2017-10685 has a high severity level due to its potential for remote arbitrary code execution.
2
How do I fix CVE-2017-10685?
To fix CVE-2017-10685, upgrade ncurses to a version later than 6.0 where the vulnerability is patched.
3
What software is affected by CVE-2017-10685?
CVE-2017-10685 affects ncurses version 6.0.
4
What type of vulnerability is CVE-2017-10685?
CVE-2017-10685 is classified as a format string vulnerability.
5
Can CVE-2017-10685 lead to data breaches?
Yes, CVE-2017-10685 can potentially lead to data breaches due to its capability for remote code execution.