CVE-2017-16879

HIGH

ncurses 6.0 - Stack-based Buffer Overflow in _nc_write_entry via Crafted Terminfo File

Title source: llm
STIX 2.1

Description

Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.

Scores

CVSS v3 7.8
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
gnu/ncurses 6.0
Published Nov 22, 2017
Tracked Since Feb 18, 2026