CVE-2020-19188
⚪ Do wiadomości
Przepełnienie bufora w ncurses umożliwia zdalnym atakującym wywołanie odmowy usługi.
CVSS
6.5
EPSS
1.8%
Exploit
poc
Vendor
invisible-island
Opis źródłowy (NVD)
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
buffer-overflow dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 1.8% |
| Opublikowano (NVD) | 2023-08-22 19:16:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:24 UTC |
Referencje
- http://seclists.org/fulldisclosure/2023/Dec/10 ([email protected])
- http://seclists.org/fulldisclosure/2023/Dec/11 ([email protected])
- http://seclists.org/fulldisclosure/2023/Dec/9 ([email protected])
- https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.md ([email protected]) [Exploit, Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20231006-0005/ ([email protected]) [Third Party Advisory]
- https://support.apple.com/kb/HT214036 ([email protected])
- https://support.apple.com/kb/HT214037 ([email protected])
- https://support.apple.com/kb/HT214038 ([email protected])