Lucene search

K
redhatcveRedhat.comRH:CVE-2021-39537
HistorySep 22, 2021 - 7:10 p.m.

CVE-2021-39537

2021-09-2219:10:18
redhat.com
access.redhat.com
26

8.5 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.2%

A heap overflow vulnerability has been found in the ncurses package, particularly in the “tic”. This flaw results from a lack of proper bounds checking during input processing. By exploiting this boundary error, an attacker can create a malicious file, deceive the victim into opening it using the affected software, and initiate an out-of-bounds write, potentially impacting system availability.

Mitigation

Do not compile untrusted terminfo descriptions.