CVE-2017-13734: Buffer Overflow
Published Aug 29, 2017
·Updated
There is an illegal address access in the ncsafestrcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.
Affected Software
2 affected components
GNU ncurses=6.0
invisible-island Ncurses=6.0
Remediation
Patch Available
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·06:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-13734?
CVE-2017-13734 is classified as a critical vulnerability due to its potential for remote denial of service attacks.
2
How do I fix CVE-2017-13734?
To fix CVE-2017-13734, upgrade to a version of ncurses later than 6.0 that has patched this vulnerability.
3
What are the consequences of CVE-2017-13734 exploitation?
Exploitation of CVE-2017-13734 can lead to a remote denial of service, causing affected applications to crash.
4
Is my ncurses installation vulnerable to CVE-2017-13734?
If you are using ncurses version 6.0, then your installation is vulnerable to CVE-2017-13734.
5
What is the primary function affected in CVE-2017-13734?
The _nc_safe_strcat function in strings.c is the primary function affected by CVE-2017-13734.