Oval Definition:oval:com.ubuntu.cosmic:def:2018107540000000
Revision Date:2018-05-04Version:1
Title:CVE-2018-10754 on Ubuntu 18.10 (cosmic) - low.
Description:In ncurses before 6.1.20180414, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service if the terminfo library code is used to process untrusted terminfo data in which a use-name is invalid syntax. The product proceeds to the dereference code path even after a "dubious character `[' in name or alias field" detection.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-10754
Platform(s):Ubuntu 18.10
Product(s):
Definition Synopsis
  • Ubuntu 18.10 (cosmic) is installed.
  • AND ncurses package in cosmic, is related to the CVE in some way and has been fixed (note: '6.1+20180210-4ubuntu1').
  • BACK