UbuntuUpdates.org

Package "ncurses-bin"

Name: ncurses-bin

Description:

terminal-related programs and man pages

Latest version: 6.4-2ubuntu0.1
Release: lunar (23.04)
Level: security
Repository: main
Head package: ncurses
Homepage: https://invisible-island.net/ncurses/

Links


Download "ncurses-bin"


Other versions of "ncurses-bin" in Lunar

Repository Area Version
base main 6.4-2
updates main 6.4-2ubuntu0.1

Changelog

Version: 6.4-2ubuntu0.1 2023-05-23 12:07:06 UTC

  ncurses (6.4-2ubuntu0.1) lunar-security; urgency=medium

  * SECURITY UPDATE: memory corruption when processing malformed terminfo data
    entries loaded by setuid/setgid programs
    - debian/patches/CVE-2023-29491-mitigation-1.patch: fix copy/paste error
      in configure.in.
    - debian/patches/CVE-2023-29491-mitigation-2.patch: change the
      --disable-root-environ configure option behavior.
    - debian/rules: set --disable-root-environ in configuration options.
    - debian/libtinfo5.symbols, debian/libtinfo6.symbols: add _nc_env_access
      to symbols files.
    - CVE-2023-29491

 -- Camila Camargo de Matos <email address hidden> Tue, 16 May 2023 15:25:33 -0300

CVE-2023-29491 ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data



About   -   Send Feedback to @ubuntu_updates