CVE-2023-45918: Null Pointer Dereference
ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/libtermcap.c.
https://lists.gnu.org/archive/html/bug-ncurses/2023-06/msg00005.html https://security.netapp.com/advisory/ntap-20240315-0006/
Other sources
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45918?
CVE-2023-45918 has been classified with a high severity due to its potential to cause a denial of service.
How do I fix CVE-2023-45918?
To fix CVE-2023-45918, update to the latest version of GNU ncurses that contains the patch for this vulnerability.
What causes the vulnerability in CVE-2023-45918?
CVE-2023-45918 is caused by a NULL pointer dereference in the tgetstr function.
Which versions of ncurses are affected by CVE-2023-45918?
ncurses version 6.4-20230610 is known to be affected by CVE-2023-45918.
Can CVE-2023-45918 be exploited remotely?
Yes, CVE-2023-45918 can potentially be exploited remotely, leading to a denial of service.