CVE
CVE-2023-29491
| CVE ID |
CVE-2023-29491
|
|---|---|
| CVSS Score |
7.8
|
| Operating System | |
| Affected Versions |
CentOS 7
|
| Patched Versions |
ncurses-5.9-14.20130511_ol001.el7_4
|
| Patch Date |
|
| Last Updated Date | |
| Vector String |
Additional Information
OL CVE Issue Summary:
Malformed data in a terminfo database file can trigger security-relevant memory corruption when ncurses is used by a setuid application. Local users can exploit this flaw via terminfo databases found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.