suse · CVE-2017-13728

Quick triage

Priority: medium Published: 2021-05-30 14:01:20 UTC Updated: 2026-04-17 15:56:51 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-13728 severity moderate: SUSE including 73 source package names (0.9.1:libncurses5-5.9-58.1, 0.9.1:libncurses6-5.9-58.1, …), 319 product×package rows across 59 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (59 product lines)): Fixed 319.

Description:

There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack.

cvelogic Threat Intelligence