CVE-2023-29491: Invisible-Island Ncurses
High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.
ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.
Affected products
- Invisible-Island Ncurses: before 6.4 (fixed in 6.4)
Published 2023-04-14. Last modified 2026-07-27.