CVE-2020-19189: Buffer Overflow
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accessibility. This issue was addressed with improved state management.
— Apple
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
AppleEvents. This issue was addressed with improved redaction of sensitive information.
— Apple
AppleGraphicsControl. Multiple memory corruption issues were addressed with improved input validation.
— Apple
AppleVA. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/ncursesto a version that resolves this vulnerability.Fixed in 6.1+20191019-1 - Upgrade
Upgrade
ubuntu/ncursesto a version that resolves this vulnerability.Fixed in 6.1-1ubuntu1.18.04.1+ - Upgrade
Upgrade
ubuntu/ncursesto a version that resolves this vulnerability.Fixed in 5.9+20140118-1ubuntu1+ - Upgrade
Upgrade
ubuntu/ncursesto a version that resolves this vulnerability.Fixed in 6.0+20160213-1ubuntu1+ - Upgrade
Upgrade
debian/ncursesto a version that resolves this vulnerability.Fixed in 6.1+20181013-2+deb10u5Fixed in 6.2+20201114-2+deb11u2Fixed in 6.4-4Fixed in 6.4+20240113-1 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.2 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.7.2 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.7.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.6.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.2 - Upgrade
Upgrade
curlto a version that resolves this vulnerability.Fixed in 8.4.0 - Upgrade
Upgrade
ncurses 6.1to a version that resolves this vulnerability.Patch tinfo/parse_entry.c:997
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42874
- CVE-2023-42937
- CVE-2023-42919
- CVE-2023-42894
- CVE-2023-42901
- CVE-2023-42902
- CVE-2023-42912
- CVE-2023-42903
- CVE-2023-42904
- CVE-2023-42905
- CVE-2023-42906
- CVE-2023-42907
- CVE-2023-42908
- CVE-2023-42909
- CVE-2023-42910
- CVE-2023-42911
- CVE-2023-42926
- CVE-2023-42882
- CVE-2023-42881
- CVE-2023-42924
- CVE-2023-42896
- CVE-2023-42884
- CVE-2023-45866
- CVE-2023-42900
- CVE-2023-42886
- CVE-2023-38545
- CVE-2023-38039
- CVE-2023-38546
- CVE-2023-42931
- CVE-2023-42892
- CVE-2023-42922
- CVE-2023-42898
- CVE-2023-42899
- CVE-2023-42888
- CVE-2023-42891
- CVE-2023-42974
- CVE-2023-42914
- CVE-2023-42893
- CVE-2023-3618
- CVE-2020-19185
- CVE-2020-19186
- CVE-2020-19187
- CVE-2020-19188
- CVE-2020-19189
- CVE-2020-19190
- CVE-2023-42887
- CVE-2023-42936
- CVE-2023-40390
- CVE-2023-42842
- CVE-2023-42930
- CVE-2023-42913
- CVE-2023-42932
- CVE-2023-42947
- CVE-2023-40389
- CVE-2023-5344
- CVE-2023-42890
- CVE-2023-42883
- CVE-2023-42950
- CVE-2023-42956
- CVE-2023-41989
- CVE-2023-42834
- CVE-2023-42838
- CVE-2023-42836
- CVE-2023-42952
- CVE-2023-43010
Frequently Asked Questions
What is the vulnerability ID for this buffer overflow vulnerability?
The vulnerability ID for this buffer overflow vulnerability is CVE-2020-19189.
Where does the buffer overflow vulnerability occur?
The buffer overflow vulnerability occurs in the postprocess_terminfo function in tinfo/parse_entry.c at line 997.
What software is affected by this buffer overflow vulnerability?
The Gnu Ncurses software version 6.1 is affected by this buffer overflow vulnerability.
How can a remote attacker exploit this buffer overflow vulnerability?
A remote attacker can exploit this buffer overflow vulnerability by sending crafted commands.
What is the severity of this buffer overflow vulnerability?
The severity of this buffer overflow vulnerability is medium, with a severity value of 6.5.