Security Advisory: CVE-2018-19211
ubi-micro-dev Opinion:
This vulnerability only exists in tools found in the
ncurses
package, and not the
ncurses-libs
package.
This container image does not include
ncurses
, hence this is a false positive.
Description:
In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
Locations:
- ncurses-libs-6.1-10.20180224.el8
References: