VDB
Sign up
—

RUSTSEC-2019-0006

Buffer overflow and format vulnerabilities in functions exposed without unsafe

Details

`ncurses` exposes functions from the ncurses library which:

- Pass buffers without length to C functions that may write an arbitrary amount of data, leading to a buffer overflow. (`instr`, `mvwinstr`, etc) - Passes rust &str to strings expecting C format arguments, allowing hostile input to execute a format string attack, which trivially allows writing arbitrary data to stack memory (functions in the `printw` family).

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/ncurses
Introduced in: 0.0.0-0

No fixed version published yet for ncurses. Pin to a known-safe version or switch to an alternative.

References