Red Hat Bugzilla – Bug 1517922
CVE-2017-16879 ncurses: Stack-based buffer overflow in the _nc_write_entry function
Last modified: 2017-11-28 04:56:12 EST
Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic. References: https://cxsecurity.com/issue/WLB-2017110106
Created ncurses tracking bugs for this issue: Affects: fedora-all [bug 1517923]
fortify source mitigates this to a crash only.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.