First published: Sat Jul 08 2017(Updated: )
In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Ncurses | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11113 has been classified as a medium severity vulnerability.
To fix CVE-2017-11113, upgrade ncurses to version 6.1 or later.
CVE-2017-11113 is a NULL Pointer Dereference vulnerability.
Yes, CVE-2017-11113 can lead to a remote denial of service attack.
CVE-2017-11113 affects ncurses version 6.0.