A NULL pointer dereference was found in the way the _nc_parse_entry function parses terminfo data for compilation. An attacker able to provide specially crafted terminfo data could use this flaw to crash the application parsing it.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | ncurses | 2018-08-08 18:08 | ALAS2-2018-1053 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 2.8 | CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L |