endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2022-29458 | ncurses-base (CWE-125) #97

Open ckalpakoglu opened 1 year ago

ckalpakoglu commented 1 year ago

Due Date: 0001-01-01

A low severity vulnerability has been discovered in your project.

Project Name: infra_duplicate_test

Scanner Name: trivy

Cwe ID: 125

Cwe Name: Out-of-bounds Read

Cwe Link: https://cwe.mitre.org/data/definitions/125.html

CVE ID: CVE-2022-29458

Target: ubuntu:latest (ubuntu 22.04)

Packages:

References:

Tool Description: ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

Custom Description: test

Kondukto Link: https://82.kondukto.local/projects/636249c73ffe9321df1a2823/vulns/appsec?page=1&perPage=15&id=in:63e4e1b7ea3ee2b41b8d86ea Deeplink: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29458

ckalpakoglu commented 1 year ago

The issue has been closed by Kondukto since it is marked as won't fix.

ckalpakoglu commented 1 year ago

The issue has been reopened by Kondukto since its won't fix/mitigated status has been removed.