[ubuntu/jammy-security] ncurses 6.3-2ubuntu0.1 (Accepted)

Camila Camargo de Matos camila.camargodematos at canonical.com
Tue May 23 10:37:42 UTC 2023


ncurses (6.3-2ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: out-of-bounds read in the convert_strings function
    - debian/patches/CVE-2022-29458.patch:add a limit-check to guard against
      corrupt terminfo data.
    - CVE-2022-29458
  * SECURITY UPDATE: memory corruption when processing malformed terminfo data
    entries loaded by setuid/setgid programs
    - debian/patches/CVE-2023-29491-mitigation-1.patch: fix copy/paste error
      in configure.in.
    - debian/patches/CVE-2023-29491-mitigation-2.patch: change the
      --disable-root-environ configure option behavior.
    - debian/rules: set --disable-root-environ in configuration options.
    - debian/libtinfo5.symbols, debian/libtinfo6.symbols: add _nc_env_access
      to symbols files.
    - CVE-2023-29491

Date: 2023-05-19 17:08:08.154202+00:00
Changed-By: Camila Camargo de Matos <camila.camargodematos at canonical.com>
https://launchpad.net/ubuntu/+source/ncurses/6.3-2ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list