ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
https://www.openwall.com/lists/oss-security/2023/04/13/4
https://www.openwall.com/lists/oss-security/2023/04/12/5
https://support.apple.com/kb/HT213845
https://support.apple.com/kb/HT213844
https://support.apple.com/kb/HT213843
https://security.netapp.com/advisory/ntap-20230517-0009/
https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html
http://www.openwall.com/lists/oss-security/2023/04/19/11
Published: 2023-04-14
Updated: 2024-01-31
Base Score: 6.8
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
Severity: Medium
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
Base Score: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical