Fedora 38: ncurses 2024-96090dafaf
Summary
The curses library routines are a terminal-independent method of
updating character screens with reasonable optimization. The ncurses
(new curses) library is a freely distributable replacement for the
discontinued 4.4 BSD classic curses library.
This package contains support utilities, including a terminfo compiler
tic, a decompiler infocmp, clear, tput, tset, and a termcap conversion
tool captoinfo.
Update Information:
Update to newer ncurses version, which fixes CVE-2023-29491 and CVE-2023-50495.
Change Log
* Tue Aug 22 2023 Miroslav Lichvar
References
[ 1 ] Bug #2191704 - CVE-2023-29491 ncurses: Local users can trigger security-relevant memory corruption via malformed data
https://bugzilla.redhat.com/show_bug.cgi?id=2191704
[ 2 ] Bug #2254244 - CVE-2023-50495 ncurses: segmentation fault via _nc_wrap_entry()
https://bugzilla.redhat.com/show_bug.cgi?id=2254244
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-96090dafaf' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html