7.2

CVE-2002-0062

Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 2.2 Edition 68k
Debian ≫ Debian Linux Version 2.2 Edition alpha
Debian ≫ Debian Linux Version 2.2 Edition arm
Debian ≫ Debian Linux Version 2.2 Edition ia-32
Debian ≫ Debian Linux Version 2.2 Edition powerpc
Debian ≫ Debian Linux Version 2.2 Edition sparc
Freebsd ≫ Freebsd Version 3.1
Freebsd ≫ Freebsd Version 3.2
Freebsd ≫ Freebsd Version 3.3
Freebsd ≫ Freebsd Version 3.4
Freebsd ≫ Freebsd Version 3.5
Freebsd ≫ Freebsd Version 3.5.1
Freebsd ≫ Freebsd Version 4.0
Freebsd ≫ Freebsd Version 4.1
Freebsd ≫ Freebsd Version 4.1.1
Freebsd ≫ Freebsd Version 5.0
Redhat ≫ Linux Version 6.1 Edition alpha
Redhat ≫ Linux Version 6.1 Edition i386
Redhat ≫ Linux Version 6.1 Edition sparc
Redhat ≫ Linux Version 7.0 Edition alpha
Redhat ≫ Linux Version 7.0 Edition i386
Redhat ≫ Linux Version 7.1 Edition alpha
Redhat ≫ Linux Version 7.1 Edition i386
Redhat ≫ Linux Version 7.2 Edition i386
Suse ≫ Suse Linux Version 6.2
Suse ≫ Suse Linux Version 6.3
Suse ≫ Suse Linux Version 7.0
Invisible-island ≫ Ncurses Version < 5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.379
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

http://www.debian.org/security/2002/dsa-113
Patch
Vendor Advisory
http://www.iss.net/security_center/static/8222.php
Third Party Advisory
http://www.securityfocus.com/bid/2116
Patch
Third Party Advisory
Vendor Advisory
VDB Entry
http://www.redhat.com/support/errata/RHSA-2002-020.html
Patch
Vendor Advisory