CVE-2017-16879: Invisible-Island Ncurses
High severity, CVSS 7.8. EPSS: 2.4% chance of exploitation in the next 30 days.
Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.
Affected products
- Invisible-Island Ncurses: version 6.0 only
Published 2017-11-22. Last modified 2026-07-23.