First published: Tue Dec 12 2023(Updated: )
NCurse is vulnerable to a denial of service, caused by a segmentation fault in the _nc_wrap_entry(). By persuading a victim to open a specially crafted content, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invisible-island Ncurse | =6.4-20230418 | |
ubuntu/ncurses | <6.1-1ubuntu1.18.04.1+ | 6.1-1ubuntu1.18.04.1+ |
ubuntu/ncurses | <5.9+20140118-1ubuntu1+ | 5.9+20140118-1ubuntu1+ |
ubuntu/ncurses | <6.4+20230625-1 | 6.4+20230625-1 |
ubuntu/ncurses | <6.0+20160213-1ubuntu1+ | 6.0+20160213-1ubuntu1+ |
debian/ncurses | <=6.1+20181013-2+deb10u2<=6.1+20181013-2+deb10u5<=6.2+20201114-2+deb11u2<=6.4-4 | 6.4+20240414-1 |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-50495 is classified as a denial of service vulnerability.
To fix CVE-2023-50495, update NCurse to version 6.4+20230625-1 or later.
NCurse version 6.4-20230418 is vulnerable to CVE-2023-50495.
Yes, CVE-2023-50495 can be exploited remotely by convincing a user to open specially crafted content.
CVE-2023-50495 facilitates a denial of service attack through a segmentation fault.