{"id":"CVE-2023-29491","title":"ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO…","summary":"ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"invisible-island","product":"ncurses","affected":["ncurses < 6.4"],"patched":["ncurses 6.4"],"published":"2023-04-14","updated":"2026-07-27","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-29491","references":[{"url":"http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2023/04/19/10","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2023/04/19/11","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20230517-0009/","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT213843","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT213844","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT213845","label":"cve@mitre.org"},{"url":"https://www.openwall.com/lists/oss-security/2023/04/12/5","label":"cve@mitre.org"},{"url":"https://www.openwall.com/lists/oss-security/2023/04/13/4","label":"cve@mitre.org"},{"url":"http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2023/04/19/10","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2023/04/19/11","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20230517-0009/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213843","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213844","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213845","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openwall.com/lists/oss-security/2023/04/12/5","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openwall.com/lists/oss-security/2023/04/13/4","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00931,"epssPercentile":0.59112,"ingestedAt":"2026-07-27T14:19:53.871Z","slug":"CVE-2023-29491","body":"## Overview\n\nncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.\n\n## Affected\n\n- `ncurses < 6.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ncurses 6.4`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}