Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-29458 | ncurses-base (CWE-125) #97

Open
ckalpakoglu opened this issue Feb 9, 2023 · 2 comments
Open

CVE-2022-29458 | ncurses-base (CWE-125) #97

ckalpakoglu opened this issue Feb 9, 2023 · 2 comments
Assignees
Labels
bug Something isn't working KONDUKTO

Comments

@ckalpakoglu
Copy link

Due Date: 0001-01-01

A low severity vulnerability has been discovered in your project.

Project Name: infra_duplicate_test

Scanner Name: trivy

Cwe ID: 125

Cwe Name: Out-of-bounds Read

Cwe Link: https://cwe.mitre.org/data/definitions/125.html

CVE ID: CVE-2022-29458

Target: ubuntu:latest (ubuntu 22.04)

Packages:

  • ncurses-base : 6.3-2 - Fixed Version:

References:

Tool Description: ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

Custom Description: test

Kondukto Link: https://82.kondukto.local/projects/636249c73ffe9321df1a2823/vulns/appsec?page=1&perPage=15&id=in:63e4e1b7ea3ee2b41b8d86ea
Deeplink: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29458

@ckalpakoglu ckalpakoglu added bug Something isn't working KONDUKTO labels Feb 9, 2023
@ckalpakoglu ckalpakoglu self-assigned this Feb 9, 2023
@ckalpakoglu ckalpakoglu added the wontfix This will not be worked on label Feb 14, 2023
@ckalpakoglu
Copy link
Author

The issue has been closed by Kondukto since it is marked as won't fix.

@ckalpakoglu ckalpakoglu reopened this Mar 23, 2023
@ckalpakoglu ckalpakoglu removed the wontfix This will not be worked on label Mar 23, 2023
@ckalpakoglu
Copy link
Author

The issue has been reopened by Kondukto since its won't fix/mitigated status has been removed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working KONDUKTO
Projects
None yet
Development

No branches or pull requests

1 participant