CVE-2017-11112: Input Validation
Published Jul 8, 2017
·Updated
In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the appendacs function of tinfo/parseentry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.
Affected Software
2 affected components
GNU ncurses=6.0
invisible-island Ncurses=6.0
Event History
Jul 8, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-11112?
CVE-2017-11112 has been classified as a medium severity vulnerability due to its potential to cause denial of service attacks.
2
How do I fix CVE-2017-11112?
To fix CVE-2017-11112, upgrade ncurses to version 6.1 or later.
3
What software is affected by CVE-2017-11112?
CVE-2017-11112 affects ncurses version 6.0.
4
Can CVE-2017-11112 lead to data loss?
CVE-2017-11112 primarily leads to denial of service and does not directly cause data loss.
5
Is my system vulnerable to CVE-2017-11112?
If you are using ncurses version 6.0, your system is vulnerable to CVE-2017-11112.