CVE-2019-17595: Invisible-Island Ncurses
Medium severity, CVSS 5.4. EPSS: 2.1% chance of exploitation in the next 30 days.
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Affected products
- Invisible-Island Ncurses: before 6.2 (fixed in 6.2)
- Opensuse Leap: version 15.0 only; version 15.1 only
Published 2019-10-14. Last modified 2026-07-27.