Skip to content

Latest commit

 

History

History
53 lines (37 loc) · 1.83 KB

File metadata and controls

53 lines (37 loc) · 1.83 KB
sidebar_label title description hide_table_of_contents sidebar_class_name toc_max_heading_level tags
CVE-2021-39537
CVE-2021-39537
Lifecycle of CVE-2021-39537
true
hide-from-sidebar
2
security
cve

CVE Details

CVE-2021-39537

Last Update

11/7/2024

NIST CVE Summary

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

Our Official Summary

This vulnerability is reported on some 3rd party images used by our products. This flaw results from a lack of proper bounds checking during input processing. By exploiting this boundary error, an attacker can create a malicious file, deceive the victim into opening it using the affected software, and initiate an out-of-bounds write, potentially impacting system availability. We are waiting on an upstream fix from the 3rd party vendor. We will upgrade the images once the upstream fix becomes available.

CVE Severity

8.8

Status

Ongoing

Affected Products & Versions

  • Palette VerteX airgap 4.4.14, 4.4.18, 4.5.3, 4.5.8
  • Palette Enterprise airgap 4.4.18, 4.5.3, 4.5.8
  • Palette VerteX 4.5.3, 4.5.8
  • Palette Enterprise 4.5.3, 4.5.8

Revision History

  • 1.0 08/16/2024 Initial Publication
  • 2.0 08/17/2024 Added Palette VerteX airgap 4.4.14 to Affected Products
  • 3.0 09/17/2024 Added Palette VerteX airgap 4.4.18 & Palette Enterprise airgap 4.4.18 to Affected Products
  • 4.0 10/10/2024 Added Palette VerteX airgap 4.5.3 & Palette Enterprise airgap 4.5.3 to Affected Products
  • 5.0 10/14/2024 Added Palette Enterprise & Palette VerteX 4.5.3 to Affected Products
  • 6.0 11/7/2024 Added Palette VerteX airgap, Palette Enterprise airgap, Palette Enterprise, and Palette VerteX 4.5.8 to Affected Products