CVE-2021-39537

Name
CVE-2021-39537
Description
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html
MISC https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html
MISC http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:ncurses:*:*:*:*:*:*:*:* ncurses >= None <= 6.2.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ncurses 3.11-main 6.1_p20200118-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
ncurses 3.12-main 6.2_p20200523-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
ncurses 3.14-main 6.2_p20210612-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
ncurses 3.13-main 6.2_p20210109-r1 Natanael Copa <ncopa@alpinelinux.org> fixed