[CLSA-2024:1710789286] ncurses: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2024-03-18 19:14:50 UTC
Description:
- CVE-2023-29491.patch: Mitigate vulnerability by building the packages with modified --disable-root-environ option which now limits usage of environment for setuid/setgid programs only - CVE-2021-39537.patch: Add a check for end-of-string in cvtchar to handle a malformed string in infotocap
Updated packages:
  • ncurses-5.9-14.20130511.el7_4.tuxcare.els1.x86_64.rpm
    sha:7622bf4a9f245736aca91a251693ab3a04038b26
  • ncurses-base-5.9-14.20130511.el7_4.tuxcare.els1.noarch.rpm
    sha:183479f9b0b27856d48542de2e485d2435942b44
  • ncurses-devel-5.9-14.20130511.el7_4.tuxcare.els1.i686.rpm
    sha:9c0188412545af40b9057488f8cc5de913906ed7
  • ncurses-devel-5.9-14.20130511.el7_4.tuxcare.els1.x86_64.rpm
    sha:3e46936a0dabf47c1197e8aefecd3c26523967e5
  • ncurses-libs-5.9-14.20130511.el7_4.tuxcare.els1.i686.rpm
    sha:56a86980b54c95d8686371cfde086c73153b4bf4
  • ncurses-libs-5.9-14.20130511.el7_4.tuxcare.els1.x86_64.rpm
    sha:f60b9a8a2ca4fed240ec3969b90dc8d92e089583
  • ncurses-static-5.9-14.20130511.el7_4.tuxcare.els1.i686.rpm
    sha:307cbb68b416b647a92adab5760e11c79650951b
  • ncurses-static-5.9-14.20130511.el7_4.tuxcare.els1.x86_64.rpm
    sha:3dd9d204c2e8a93ff3c6d58513adcedae1749898
  • ncurses-term-5.9-14.20130511.el7_4.tuxcare.els1.noarch.rpm
    sha:96e7a53040dcb3ee7648cd34a0d9f8233789f960
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.