CVE-2018-19211: Invisible-Island Ncurses

Medium severity, CVSS 5.5. EPSS: 0.9% chance of exploitation in the next 30 days.

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

Affected products

Published 2018-11-12. Last modified 2026-07-23.