Vulnerability Name:

CVE-2021-39537 (CCN-209855)

Assigned:2020-08-04
Published:2020-08-04
Updated:2023-04-27
Summary:
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
8.0 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2021-39537

Source: cve@mitre.org
Type: Patch, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: XF
Type: UNKNOWN
ncurses-cve202139537-bo(209855)

Source: CCN
Type: GNU Mailing List, Tue, 4 Aug 2020 21:26:04 +0800
A heap-buffer-overflow in captoinfo.c:321:12

Source: cve@mitre.org
Type: Exploit, Mailing List, Vendor Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Vendor Advisory
cve@mitre.org

Source: cve@mitre.org
Type: UNKNOWN
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:gnu:ncurses:4.2:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:ncurses:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:ncurses:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:ncurses:5.9:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:ncurses:6.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8042
    P
    ncurses-devel-32bit-6.1-150000.5.15.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7622
    P
    libncurses6-32bit-6.1-150000.5.15.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8083
    P
    libncurses5-32bit-6.1-150000.5.15.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:794
    P
    Security update for slurm (Important)
    2022-10-03
    oval:org.opensuse.security:def:95415
    P
    Security update for resource-agents (Important)
    2022-07-07
    oval:org.opensuse.security:def:3409
    P
    xrdp-0.9.10-1.35 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3507
    P
    gnutls-3.3.27-3.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3441
    P
    avahi-0.6.32-32.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3695
    P
    libvdpau1-1.1.1-6.73 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3037
    P
    cpio-2.11-36.3.4 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94667
    P
    libncurses6-32bit-6.1-5.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94619
    P
    libXvMC-devel-1.0.10-1.23 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95039
    P
    ncurses-devel-32bit-6.1-5.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94924
    P
    libSoundTouch0-1.8.0-3.11.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95071
    P
    libncurses5-32bit-6.1-5.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:4584
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 12 SP5) (Important)
    2022-04-25
    oval:org.opensuse.security:def:101637
    P
    Security update for net-snmp (Important)
    2022-01-11
    oval:org.opensuse.security:def:4515
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 12 SP5) (Important)
    2021-11-17
    oval:org.opensuse.security:def:102298
    P
    Security update for samba and ldb (Important)
    2021-11-10
    oval:org.opensuse.security:def:111108
    P
    Security update for ncurses (Moderate)
    2021-10-31
    oval:org.opensuse.security:def:74672
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:99152
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:5141
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:65673
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:93765
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:6483
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:100669
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:108794
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:67572
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:64596
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:93107
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:74741
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:1133
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:5867
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:99424
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:26154
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:95585
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:117512
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:111759
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:66956
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:93979
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:73718
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:101811
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:102128
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:108964
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:64784
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:93267
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:76024
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:1221
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:6208
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:99687
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:33029
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:87493
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:117817
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:107998
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:67297
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:94191
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:58852
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:42131
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:73906
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:101881
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:65604
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:93581
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:76365
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:6458
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:100340
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:34573
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:101332
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:117887
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:108303
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:67547
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:94402
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:60396
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:42230
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:40620
    P
    Security update for ncurses (Moderate)
    2021-10-18
    oval:org.opensuse.security:def:43672
    P
    Security update for ncurses (Moderate)
    2021-10-18
    oval:org.opensuse.security:def:45050
    P
    Security update for ncurses (Moderate)
    2021-10-18
    oval:org.opensuse.security:def:39242
    P
    Security update for ncurses (Moderate)
    2021-10-18
    BACK
    gnu ncurses 4.2
    gnu ncurses 5.0
    gnu ncurses 6.0
    gnu ncurses 5.9
    gnu ncurses 6.1