HIGH7.5
GHSA-32v7-ghpr-c8hg
Mishandling of format strings in ncurses
Details
ncurses exposes functions from the ncurses library which: * Pass buffers without length to C functions that may write an arbitrary amount of data, leading to a buffer overflow. (instr, mvwinstr, etc) * Passes rust &str to strings expecting C format arguments, allowing hostile input to execute a format string attack, which trivially allows writing arbitrary data to stack memory (functions in the printw family).
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/ncurses
Introduced in:
0No fixed version published yet for ncurses. Pin to a known-safe version or switch to an alternative.