7.2
CVE-2002-0062
- EPSS 0.49%
- Veröffentlicht 08.03.2002 05:00:00
- Zuletzt bearbeitet 23.07.2026 18:58:25
- Erkennungen
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 2.2 Edition 68k
Debian ≫ Debian Linux Version 2.2 Edition alpha
Debian ≫ Debian Linux Version 2.2 Edition arm
Debian ≫ Debian Linux Version 2.2 Edition ia-32
Debian ≫ Debian Linux Version 2.2 Edition powerpc
Debian ≫ Debian Linux Version 2.2 Edition sparc
Suse ≫ Suse Linux Version 6.2
Suse ≫ Suse Linux Version 6.3
Suse ≫ Suse Linux Version 7.0
Invisible-island ≫ Ncurses Version < 5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.379 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
http://www.debian.org/security/2002/dsa-113
http://www.iss.net/security_center/static/8222.php
http://www.securityfocus.com/bid/2116
http://www.redhat.com/support/errata/RHSA-2002-020.html