ELA-967-1 ncurses security update

out-of-bounds read problem

2023-09-28
Packagencurses
Version5.9+20140913-1+deb8u5 (jessie), 6.0+20161126-1+deb9u4 (stretch)
Related CVEs CVE-2020-19189


An out-of-bounds read problem was found in the postprocess_terminfo function of ncurses, a text-based user interface toolkit, which could potentially lead to an exposure of sensitive information or denial of service.



For Debian 8 jessie, these problems have been fixed in version 5.9+20140913-1+deb8u5.

For Debian 9 stretch, these problems have been fixed in version 6.0+20161126-1+deb9u4.

We recommend that you upgrade your ncurses packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.