In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "negligible", "binaries": [ { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32ncurses5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32ncurses5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32ncurses5-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32ncurses5-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32ncursesw5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32ncursesw5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32ncursesw5-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32ncursesw5-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32tinfo-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32tinfo-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32tinfo5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib32tinfo5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib64ncurses5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib64ncurses5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib64ncurses5-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib64ncurses5-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib64tinfo5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "lib64tinfo5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncurses5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncurses5-dbg" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncurses5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncurses5-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncurses5-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncursesw5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncursesw5-dbg" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncursesw5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncursesw5-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libncursesw5-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libtinfo-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libtinfo-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libtinfo5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libtinfo5-dbg" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libtinfo5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32ncurses5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32ncurses5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32ncurses5-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32ncurses5-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32ncursesw5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32ncursesw5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32ncursesw5-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32ncursesw5-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32tinfo-dev" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32tinfo-dev-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32tinfo5" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "libx32tinfo5-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "ncurses-base" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "ncurses-bin" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "ncurses-bin-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "ncurses-doc" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "ncurses-examples" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "ncurses-examples-dbgsym" }, { "binary_version": "5.9+20140118-1ubuntu1+esm1", "binary_name": "ncurses-term" } ] }
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "negligible", "binaries": [ { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32ncurses5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32ncurses5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32ncurses5-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32ncurses5-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32ncursesw5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32ncursesw5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32ncursesw5-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32ncursesw5-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32tinfo-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32tinfo-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32tinfo5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib32tinfo5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib64ncurses5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib64ncurses5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib64ncurses5-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib64ncurses5-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib64tinfo5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "lib64tinfo5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncurses5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncurses5-dbg" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncurses5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncurses5-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncurses5-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncursesw5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncursesw5-dbg" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncursesw5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncursesw5-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libncursesw5-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libtinfo-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libtinfo-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libtinfo5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libtinfo5-dbg" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libtinfo5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32ncurses5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32ncurses5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32ncurses5-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32ncurses5-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32ncursesw5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32ncursesw5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32ncursesw5-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32ncursesw5-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32tinfo-dev" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32tinfo-dev-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32tinfo5" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "libx32tinfo5-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "ncurses-base" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "ncurses-bin" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "ncurses-bin-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "ncurses-doc" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "ncurses-examples" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "ncurses-examples-dbgsym" }, { "binary_version": "6.0+20160213-1ubuntu1+esm1", "binary_name": "ncurses-term" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "negligible", "binaries": [ { "binary_version": "6.1-1ubuntu1", "binary_name": "lib32ncurses5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib32ncurses5-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib32ncurses5-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib32ncursesw5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib32ncursesw5-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib32ncursesw5-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib32tinfo-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib32tinfo5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib32tinfo5-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib64ncurses5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib64ncurses5-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib64ncurses5-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib64tinfo5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "lib64tinfo5-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libncurses5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libncurses5-dbg" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libncurses5-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libncursesw5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libncursesw5-dbg" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libncursesw5-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libtinfo-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libtinfo5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libtinfo5-dbg" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libtinfo5-udeb" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libx32ncurses5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libx32ncurses5-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libx32ncurses5-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libx32ncursesw5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libx32ncursesw5-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libx32ncursesw5-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libx32tinfo-dev" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libx32tinfo5" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "libx32tinfo5-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "ncurses-base" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "ncurses-bin" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "ncurses-bin-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "ncurses-doc" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "ncurses-examples" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "ncurses-examples-dbgsym" }, { "binary_version": "6.1-1ubuntu1", "binary_name": "ncurses-term" } ] }