USN-6684-1: ncurses vulnerability
Published Mar 7, 2024
·Updated
It was discovered that ncurses incorrectly handled certain function return values, possibly leading to segmentation fault. A local attacker could possibly use this to cause a denial of service (system crash).
Affected Software
48 affected componentsFixes available
All of the following
ubuntu/lib32ncurses5<6.1-1ubuntu1.18.04.1+esm2
6.1-1ubuntu1.18.04.1+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/lib32tinfo5<6.1-1ubuntu1.18.04.1+esm2
6.1-1ubuntu1.18.04.1+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/lib64ncurses5<6.1-1ubuntu1.18.04.1+esm2
6.1-1ubuntu1.18.04.1+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/lib64tinfo5<6.1-1ubuntu1.18.04.1+esm2
6.1-1ubuntu1.18.04.1+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libncurses5<6.1-1ubuntu1.18.04.1+esm2
6.1-1ubuntu1.18.04.1+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libtinfo5<6.1-1ubuntu1.18.04.1+esm2
6.1-1ubuntu1.18.04.1+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libx32ncurses5<6.1-1ubuntu1.18.04.1+esm2
6.1-1ubuntu1.18.04.1+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libx32tinfo5<6.1-1ubuntu1.18.04.1+esm2
6.1-1ubuntu1.18.04.1+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/lib32ncurses5<6.0+20160213-1ubuntu1+esm5
6.0+20160213-1ubuntu1+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/lib32tinfo5<6.0+20160213-1ubuntu1+esm5
6.0+20160213-1ubuntu1+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/lib64ncurses5<6.0+20160213-1ubuntu1+esm5
6.0+20160213-1ubuntu1+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/lib64tinfo5<6.0+20160213-1ubuntu1+esm5
6.0+20160213-1ubuntu1+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libncurses5<6.0+20160213-1ubuntu1+esm5
6.0+20160213-1ubuntu1+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libtinfo5<6.0+20160213-1ubuntu1+esm5
6.0+20160213-1ubuntu1+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libx32ncurses5<6.0+20160213-1ubuntu1+esm5
6.0+20160213-1ubuntu1+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libx32tinfo5<6.0+20160213-1ubuntu1+esm5
6.0+20160213-1ubuntu1+esm5
Ubuntu Ubuntu=16.04
All of the following
ubuntu/lib32ncurses5<5.9+20140118-1ubuntu1+esm5
5.9+20140118-1ubuntu1+esm5
Ubuntu Ubuntu=14.04
All of the following
ubuntu/lib32tinfo5<5.9+20140118-1ubuntu1+esm5
5.9+20140118-1ubuntu1+esm5
Ubuntu Ubuntu=14.04
All of the following
ubuntu/lib64ncurses5<5.9+20140118-1ubuntu1+esm5
5.9+20140118-1ubuntu1+esm5
Ubuntu Ubuntu=14.04
All of the following
ubuntu/lib64tinfo5<5.9+20140118-1ubuntu1+esm5
5.9+20140118-1ubuntu1+esm5
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libncurses5<5.9+20140118-1ubuntu1+esm5
5.9+20140118-1ubuntu1+esm5
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libtinfo5<5.9+20140118-1ubuntu1+esm5
5.9+20140118-1ubuntu1+esm5
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libx32ncurses5<5.9+20140118-1ubuntu1+esm5
5.9+20140118-1ubuntu1+esm5
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libx32tinfo5<5.9+20140118-1ubuntu1+esm5
5.9+20140118-1ubuntu1+esm5
Ubuntu Ubuntu=14.04
Event History
Mar 7, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6684-1?
USN-6684-1 is classified as a medium severity vulnerability that can potentially lead to a denial of service.
2
How do I fix USN-6684-1?
To fix USN-6684-1, you should upgrade to version 6.1-1ubuntu1.18.04.1+esm2 of the affected packages.
3
What packages are affected by USN-6684-1?
The affected packages in USN-6684-1 include lib32ncurses5, lib32tinfo5, lib64ncurses5, lib64tinfo5, libncurses5, and libtinfo5.
4
Who can exploit USN-6684-1?
A local attacker could exploit USN-6684-1 to cause a segmentation fault and potentially crash the system.
5
Which versions of Ubuntu are affected by USN-6684-1?
USN-6684-1 affects Ubuntu 18.04 and earlier versions.