First published: Fri Feb 16 2024(Updated: )
ncurses 6.4-20230610 has a NULL pointer dereference in tgetstr in tinfo/lib_termcap.c. <a href="https://lists.gnu.org/archive/html/bug-ncurses/2023-06/msg00005.html">https://lists.gnu.org/archive/html/bug-ncurses/2023-06/msg00005.html</a> <a href="https://security.netapp.com/advisory/ntap-20240315-0006/">https://security.netapp.com/advisory/ntap-20240315-0006/</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ncurses |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45918 has been classified with a high severity due to its potential to cause a denial of service.
To fix CVE-2023-45918, update to the latest version of GNU ncurses that contains the patch for this vulnerability.
CVE-2023-45918 is caused by a NULL pointer dereference in the tgetstr function.
ncurses version 6.4-20230610 is known to be affected by CVE-2023-45918.
Yes, CVE-2023-45918 can potentially be exploited remotely, leading to a denial of service.