CVE-2019-17594: Invisible-Island Ncurses
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Affected products
- Invisible-Island Ncurses: before 6.2 (fixed in 6.2)
- Opensuse Leap: version 15.0 only; version 15.1 only
Published 2019-10-14. Last modified 2026-07-27.