[ubuntu/bionic-updates] ncurses 6.1-1ubuntu1.18.04.1 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Tue May 23 11:28:12 UTC 2023
ncurses (6.1-1ubuntu1.18.04.1) bionic-security; urgency=medium
* SECURITY UPDATE: heap buffer overflow in the _nc_find_entry function
- debian/patches/CVE-2019-17594.patch: check for invalid hashcode in
_nc_find_type_entry and _nc_find_entry.
- CVE-2019-17594.patch
* SECURITY UPDATE: heap buffer overflow in the fmt_entry function
- debian/patches/CVE-2019-17595.patch: check for missing character after
backslash in fmt_entry.
- CVE-2019-17595
* SECURITY UPDATE: heap buffer overflow in the _nc_captoinfo function
- debian/patches/CVE-2021-39537.patch: add a check for end-of-string in
cvtchar to handle a malformed string in infotocap.
- CVE-2021-39537
* SECURITY UPDATE: out-of-bounds read in the convert_strings function
- debian/patches/CVE-2022-29458.patch:add a limit-check to guard against
corrupt terminfo data.
- CVE-2022-29458
* SECURITY UPDATE: memory corruption when processing malformed terminfo data
entries loaded by setuid/setgid programs
- debian/patches/CVE-2023-29491-mitigation.patch: change the
--disable-root-environ configure option behavior.
- debian/rules: set --disable-root-environ in configuration options.
- debian/libtinfo5.symbols: add _nc_env_access to symbols files.
- CVE-2023-29491
* debian/patches/fix-off-by-one-loop-convert-strings.patch: correct an
off-by-one loop-limit in convert_strings function.
* debian/patches/fix-tic-infloop.diff: modify tic to exit if it cannot
remove a conflicting name.
* debian/patches/fix-write_it.diff: check for missing character after
backslash in write_it.
Date: 2023-05-18 21:47:07.764770+00:00
Changed-By: Camila Camargo de Matos <camila.camargodematos at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/ncurses/6.1-1ubuntu1.18.04.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Bionic-changes
mailing list