Ubuntu Security Notice 5477-1 - Hosein Askari discovered that ncurses was incorrectly performing memory management operations when dealing with long filenames while writing structures into the file system. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. Chung-Yi Lin discovered that ncurses was incorrectly handling access to invalid memory areas when parsing terminfo or termcap entries where the use-name had invalid syntax. An attacker could possibly use this issue to cause a denial of service.
c875ea9f5728bc60c9bfeafd7fc67e19e834562f07e2806fd5a78bbedbb3d9b6
Gentoo Linux Security Advisory 201804-13 - Multiple vulnerabilities have been found in ncurses, the worst of which allows remote attackers to execute arbitrary code. Versions less than 6.1:0 are affected.
4c4788903a772dcefe050e72bf574cee08b69dcaf09683baa8c456155cb5c595
tic in the GNU ncurses library version 6.0 suffers from a buffer overflow condition that can cause a denial of service.
6739311f66a5050089a0e5b6f3cbd70ac4d655cb2d7168b82cbef694bb3cfbc3