FlawAtlas
Search the atlas
SUSE-SU-2017:1815-1 Not scored

Recommended update for ncurses

This update for ncurses fixes the following issues: Security issues fixed: - CVE-2017-10684: Possible RCE via stack-based buffer overflow in the fmt_entry function. (bsc#1046858) - CVE-2017-10685: Possible RCE with format string vulnerability in the fmt_entry function. (bsc#1046853) Bugfixes: - Drop patch ncurses-5.9-environment.dif as YaST2 ncurses GUI does not need it anymore and as well as it causes bug bsc#1000662

Exploit probability Not scored
Published July 7, 2017
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 SP2 ncurses
SUSE:Linux Enterprise Server 12 SP2 ncurses
SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2 ncurses
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 ncurses
SUSE:Linux Enterprise Software Development Kit 12 SP2 ncurses

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2017:1815-1

This update for ncurses fixes the following issues: Security issues fixed: - CVE-2017-10684: Possible RCE via stack-based buffer overflow in the fmt_entry function. (bsc#1046858) - CVE-2017-10685: Possible RCE with format string vulnerability in the fmt_entry function. (bsc#1046853) Bugfixes: - Drop patch ncurses-5.9-environment.dif as YaST2 ncurses GUI does not need it anymore and as well as it causes bug bsc#1000662

View original source

05 / REFERENCES

Further evidence