---
id: CVE-2023-29491
title: >-
  ncurses before 6.4 20230408, when used by a setuid application, allows local
  users to trigger security-relevant memory corruption via malformed data in a
  terminfo database file that is found in $HOME/.terminfo or reached via the
  TERMINFO…
summary: >-
  ncurses before 6.4 20230408, when used by a setuid application, allows local
  users to trigger security-relevant memory corruption via malformed data in a
  terminfo database file that is found in $HOME/.terminfo or reached via the
  TERMINFO…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: invisible-island
product: ncurses
affected:
  - ncurses < 6.4
patched:
  - ncurses 6.4
published: '2023-04-14'
updated: '2026-07-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-29491'
references:
  - url: >-
      http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2023/04/19/10'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2023/04/19/11'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20230517-0009/'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213843'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213844'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213845'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2023/04/12/5'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2023/04/13/4'
    label: cve@mitre.org
  - url: >-
      http://ncurses.scripts.mit.edu/?p=ncurses.git%3Ba=commit%3Bh=eb51b1ea1f75a0ec17c9c5937cb28df1e8eeec56
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2023/04/19/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2023/04/19/11'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20230517-0009/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213843'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213844'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213845'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openwall.com/lists/oss-security/2023/04/12/5'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openwall.com/lists/oss-security/2023/04/13/4'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00931
epssPercentile: 0.58927
ingestedAt: '2026-07-27T14:19:53.871Z'
---

## Overview

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

## Affected

- `ncurses < 6.4`

## Remediation

Upgrade past the affected range:

- `ncurses 6.4`
