Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-29491
HistoryApr 14, 2023 - 1:15 a.m.

CVE-2023-29491

2023-04-1401:15:08
Alpine Linux Development Team
security.alpinelinux.org
155
cve-2023-29491
memory corruption
terminfo database

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0

Percentile

5.1%

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

OSVersionArchitecturePackageVersionFilename
Alpineedge-mainnoarchncurses< 6.4_p20230424-r0UNKNOWN
Alpine3.15-mainnoarchncurses< 6.3_p20211120-r2UNKNOWN
Alpine3.16-mainnoarchncurses< 6.3_p20220521-r1UNKNOWN
Alpine3.17-mainnoarchncurses< 6.3_p20221119-r1UNKNOWN
Alpine3.19-mainnoarchncurses< 6.4_p20230424-r0UNKNOWN
Alpine3.20-mainnoarchncurses< 6.4_p20230424-r0UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0

Percentile

5.1%