CVE-2017-16879: Buffer Overflow
Published Nov 22, 2017
·Updated
Stack-based buffer overflow in the ncwriteentry function in tinfo/writeentry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.
Affected Software
2 affected components
GNU ncurses=6.0
invisible-island Ncurses=6.0
Event History
Nov 22, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2017-16879?
CVE-2017-16879 is a vulnerability in ncurses 6.0 that allows attackers to cause a denial of service or potentially execute arbitrary code.
2
How does CVE-2017-16879 work?
CVE-2017-16879 is a stack-based buffer overflow vulnerability in the _nc_write_entry function in ncurses 6.0.
3
What is the severity of CVE-2017-16879?
CVE-2017-16879 has a severity score of 7.8 (high).
4
How can CVE-2017-16879 be fixed?
Updating to a patched version of ncurses can fix CVE-2017-16879.
5
Where can I find more information about CVE-2017-16879?
You can find more information about CVE-2017-16879 at the following references: [1] [2] [3].