Debian: 'ncurses' buffer overflows
Debian The version of the ncurses display library shipped with Debian GNU/Linux 2.2is vulnerable to several buffer overflows in the parsing of terminfodatabase files.

Debian Security Advisory                                                   Daniel Jacobowitz
November 21, 2000
Package: ncurses
Vulnerability: local privilege escalation
Debian-specific: no
Vulnerable: yes

The version of the ncurses display library shipped with Debian GNU/Linux 2.2
is vulnerable to several buffer overflows in the parsing of terminfo
database files.  This problem was discovered by Jouko Pynnönen
<>. The problems are only exploitable in the presence of
setuid binaries linked to ncurses which use these particular functions,
including xmcd versions before 2.5pl1-7.1.

This problem is fixed in ncurses 5.0-6.0potato1 for Debian GNU/Linux 2.2,
and in ncurses 5.0-8 for Debian Unstable.

Debian GNU/Linux 2.1 alias slink
  Slink is no longer being supported by the Debian Security Team.  We highly
  recommend an upgrade to the current stable release.

Debian GNU/Linux 2.2 (stable) alias potato
  Fixes are currently available for the Alpha, ARM, Intel ia32, Motorola 680x0,
  PowerPC and Sun SPARC architectures, and will be included in 2.2r2.

Debian GNU/Linux Unstable alias woody
  This version of Debian is not yet released.

  Fixes will be made available for Alpha, ARM, Intel ia32, Motorola 680x0,
  PowerPC, and SPARC in the Debian archive over the next several days.

