CVE-2023-50495: Medium severity ibm cognos analytics vulnerability
NCurse is vulnerable to a denial of service, caused by a segmentation fault in the ncwrapentry(). By persuading a victim to open a specially crafted content, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component ncwrapentry().
— Ubuntu
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50495?
The severity of CVE-2023-50495 is classified as a denial of service vulnerability.
How do I fix CVE-2023-50495?
To fix CVE-2023-50495, update NCurse to version 6.4+20230625-1 or later.
Which versions of NCurse are affected by CVE-2023-50495?
NCurse version 6.4-20230418 is vulnerable to CVE-2023-50495.
Can CVE-2023-50495 be exploited remotely?
Yes, CVE-2023-50495 can be exploited remotely by convincing a user to open specially crafted content.
What type of attack does CVE-2023-50495 facilitate?
CVE-2023-50495 facilitates a denial of service attack through a segmentation fault.