Review reviewHigh
CVE-2021-39537
ncurses, mac os x
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
- CVSS
- 8.8
- EPSS
- 3.23% 87.0% percentile
- CISA KEV
- Not listed
- Published
- 2021.09.21
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
The CVSS severity warrants an early asset and exposure review.
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
Confirm exposure before applying a vendor-supported change.
Confirm that ncurses, mac os x and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.