Lucene search

K
osvGoogleOSV:RUSTSEC-2019-0006
HistoryJun 15, 2019 - 12:00 p.m.

Buffer overflow and format vulnerabilities in functions exposed without unsafe

2019-06-1512:00:00
Google
osv.dev
9

0.003 Low

EPSS

Percentile

65.2%

ncurses exposes functions from the ncurses library which:

  • Pass buffers without length to C functions that may write an arbitrary amount of
    data, leading to a buffer overflow. (instr, mvwinstr, etc)
  • Passes rust &str to strings expecting C format arguments, allowing hostile
    input to execute a format string attack, which trivially allows writing
    arbitrary data to stack memory (functions in the printw family).

0.003 Low

EPSS

Percentile

65.2%