{"id":"SUSE-SU-2019:3094-1","summary":"Security update for ncurses","details":"This update for ncurses fixes the following issues:\n\nSecurity issue fixed:\n\n- CVE-2018-10754: Fixed a denial of service caused by a NULL Pointer Dereference in the _nc_parse_entry() (bsc#1131830).\n- CVE-2019-17594: Fixed a heap-based buffer over-read in _nc_find_entry function in tinfo/comp_hash.c (bsc#1154036).\n- CVE-2019-17595: Fixed a heap-based buffer over-read in fmt_entry function in tinfo/comp_hash.c (bsc#1154037).\n\nBug fixes:\n\n- Fixed ppc64le build configuration (bsc#1134550).\n","modified":"2026-03-11T07:11:53.575297Z","published":"2019-11-28T15:48:05Z","related":["CVE-2018-10754","CVE-2019-17594","CVE-2019-17595"],"upstream":["CVE-2018-10754","CVE-2019-17594","CVE-2019-17595"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20193094-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1131830"},{"type":"REPORT","url":"https://bugzilla.suse.com/1134550"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154036"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-10754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17594"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17595"}],"affected":[{"package":{"name":"ncurses","ecosystem":"SUSE:Linux Enterprise Desktop 12 SP4","purl":"pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.9-69.1"}]}],"ecosystem_specific":{"binaries":[{"terminfo-base":"5.9-69.1","terminfo":"5.9-69.1","libncurses5-32bit":"5.9-69.1","libncurses6-32bit":"5.9-69.1","ncurses-devel":"5.9-69.1","tack":"5.9-69.1","libncurses5":"5.9-69.1","libncurses6":"5.9-69.1","ncurses-utils":"5.9-69.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3094-1.json"}},{"package":{"name":"ncurses","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP4","purl":"pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.9-69.1"}]}],"ecosystem_specific":{"binaries":[{"ncurses-devel":"5.9-69.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3094-1.json"}},{"package":{"name":"ncurses","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.9-69.1"}]}],"ecosystem_specific":{"binaries":[{"ncurses-devel":"5.9-69.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3094-1.json"}},{"package":{"name":"ncurses","ecosystem":"SUSE:Linux Enterprise Server 12 SP4","purl":"pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.9-69.1"}]}],"ecosystem_specific":{"binaries":[{"libncurses5":"5.9-69.1","ncurses-devel":"5.9-69.1","ncurses-utils":"5.9-69.1","tack":"5.9-69.1","terminfo":"5.9-69.1","libncurses5-32bit":"5.9-69.1","libncurses6-32bit":"5.9-69.1","libncurses6":"5.9-69.1","ncurses-devel-32bit":"5.9-69.1","terminfo-base":"5.9-69.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3094-1.json"}},{"package":{"name":"ncurses","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.9-69.1"}]}],"ecosystem_specific":{"binaries":[{"libncurses5-32bit":"5.9-69.1","libncurses5":"5.9-69.1","libncurses6-32bit":"5.9-69.1","libncurses6":"5.9-69.1","ncurses-devel-32bit":"5.9-69.1","tack":"5.9-69.1","ncurses-devel":"5.9-69.1","ncurses-utils":"5.9-69.1","terminfo-base":"5.9-69.1","terminfo":"5.9-69.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3094-1.json"}},{"package":{"name":"ncurses","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.9-69.1"}]}],"ecosystem_specific":{"binaries":[{"libncurses5-32bit":"5.9-69.1","libncurses5":"5.9-69.1","tack":"5.9-69.1","libncurses6-32bit":"5.9-69.1","libncurses6":"5.9-69.1","ncurses-devel-32bit":"5.9-69.1","ncurses-devel":"5.9-69.1","ncurses-utils":"5.9-69.1","terminfo-base":"5.9-69.1","terminfo":"5.9-69.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3094-1.json"}},{"package":{"name":"ncurses","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.9-69.1"}]}],"ecosystem_specific":{"binaries":[{"libncurses5-32bit":"5.9-69.1","libncurses5":"5.9-69.1","libncurses6":"5.9-69.1","ncurses-devel":"5.9-69.1","terminfo-base":"5.9-69.1","libncurses6-32bit":"5.9-69.1","ncurses-devel-32bit":"5.9-69.1","ncurses-utils":"5.9-69.1","tack":"5.9-69.1","terminfo":"5.9-69.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3094-1.json"}}],"schema_version":"1.7.5"}