There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2017-13732.json"