Candidate: CVE-2021-39537 PublicDate: 2021-09-20 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39537 https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html Description: An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow. Ubuntu-Description: Notes: mdeslaur> read of size 1, DoS only Mitigation: Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_ncurses: upstream: https://github.com/mirror/ncurses/commit/790a85dbd4a81d5f5d8dd02a44d84f01512ef443 upstream_ncurses: released (6.3) trusty_ncurses: ignored (out of standard support) trusty/esm_ncurses: needs-triage xenial_ncurses: ignored (out of standard support) esm-infra/xenial_ncurses: needs-triage bionic_ncurses: needs-triage focal_ncurses: needs-triage hirsute_ncurses: ignored (reached end-of-life) impish_ncurses: not-affected (6.2+20201114-2build1) jammy_ncurses: not-affected (6.3-2) devel_ncurses: not-affected (6.3-2)