Package "lib64ncurses5-dev"
Name: |
lib64ncurses5-dev
|
Description: |
developer's libraries for ncurses (64-bit)
|
Latest version: |
6.1-1ubuntu1.18.04.1 |
Release: |
bionic (18.04) |
Level: |
updates |
Repository: |
main |
Head package: |
ncurses |
Homepage: |
https://invisible-island.net/ncurses/ |
Links
Download "lib64ncurses5-dev"
Other versions of "lib64ncurses5-dev" in Bionic
Changelog
ncurses (6.1-1ubuntu1.18.04.1) bionic-security; urgency=medium
* SECURITY UPDATE: heap buffer overflow in the _nc_find_entry function
- debian/patches/CVE-2019-17594.patch: check for invalid hashcode in
_nc_find_type_entry and _nc_find_entry.
- CVE-2019-17594.patch
* SECURITY UPDATE: heap buffer overflow in the fmt_entry function
- debian/patches/CVE-2019-17595.patch: check for missing character after
backslash in fmt_entry.
- CVE-2019-17595
* SECURITY UPDATE: heap buffer overflow in the _nc_captoinfo function
- debian/patches/CVE-2021-39537.patch: add a check for end-of-string in
cvtchar to handle a malformed string in infotocap.
- CVE-2021-39537
* SECURITY UPDATE: out-of-bounds read in the convert_strings function
- debian/patches/CVE-2022-29458.patch:add a limit-check to guard against
corrupt terminfo data.
- CVE-2022-29458
* SECURITY UPDATE: memory corruption when processing malformed terminfo data
entries loaded by setuid/setgid programs
- debian/patches/CVE-2023-29491-mitigation.patch: change the
--disable-root-environ configure option behavior.
- debian/rules: set --disable-root-environ in configuration options.
- debian/libtinfo5.symbols: add _nc_env_access to symbols files.
- CVE-2023-29491
* debian/patches/fix-off-by-one-loop-convert-strings.patch: correct an
off-by-one loop-limit in convert_strings function.
* debian/patches/fix-tic-infloop.diff: modify tic to exit if it cannot
remove a conflicting name.
* debian/patches/fix-write_it.diff: check for missing character after
backslash in write_it.
-- Camila Camargo de Matos <email address hidden> Tue, 16 May 2023 15:54:45 -0300
|
Source diff to previous version |
CVE-2019-17594 |
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012. |
CVE-2019-17595 |
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012. |
CVE-2021-39537 |
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow. |
CVE-2022-29458 |
ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo libra |
CVE-2023-29491 |
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data |
|
ncurses (6.1-1ubuntu1.18.04) bionic-proposed; urgency=medium
* SRU: LP: #1772872: Backport changes from 6.1+20180210-4:
* Move screen.xterm-256color and rxvt-unicode-256color terminfo entries
from ncurses-term to ncurses-base (Closes: #898666, #898948).
* Cherry-pick a fix from the 20180414 patchlevel: add a null-pointer
check in _nc_parse_entry to handle an error when a use-name is invalid
syntax (report by Chung-Yi Lin, CVE-2018-10754).
-- Matthias Klose <email address hidden> Wed, 23 May 2018 10:08:27 +0200
|
1772872 |
Provide screen.xterm-256color and rxvt-unicode-256color terminfo entries in ncurses-base |
898666 |
ncurses-base: include screen.xterm-256color terminfo entry - Debian Bug report logs |
CVE-2018-10754 |
In ncurses before 6.1.20180414, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote |
|
About
-
Send Feedback to @ubuntu_updates