High severity8.8NVD Advisory· Published Sep 20, 2021· Updated Jul 27, 2026
CVE-2021-39537
CVE-2021-39537
Description
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19- cpe:2.3:o:apple:mac_os_x:10.12.6:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:11.7:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:macos:11.7:*:*:*:*:*:*:*
- cpe:2.3:o:apple:macos:13.0:*:*:*:*:*:*:*
- ncurses/ncursesdescription
- osv-coords13 versionspkg:rpm/opensuse/ncurses&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/ncurses&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Micro%205.0pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP2pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP3pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/ncurses&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 6.1-lp152.8.3.1+ 12 more
- (no CPE)range: < 6.1-lp152.8.3.1
- (no CPE)range: < 6.1-5.9.1
- (no CPE)range: < 6.1-5.9.1
- (no CPE)range: < 6.1-5.9.1
- (no CPE)range: < 6.1-5.9.1
- (no CPE)range: < 6.1-5.9.1
- (no CPE)range: < 6.1-5.9.1
- (no CPE)range: < 6.1-5.9.1
- (no CPE)range: < 6.1-5.9.1
- (no CPE)range: < 6.1-5.9.1
- (no CPE)range: < 5.9-75.1
- (no CPE)range: < 5.9-75.1
- (no CPE)range: < 5.9-75.1
Patches
Vulnerability mechanics
References
12- cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.cnvdPatchThird Party Advisory
- lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.htmlnvdExploitMailing ListVendor Advisory
- seclists.org/fulldisclosure/2022/Oct/28nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/Oct/41nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/Oct/43nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2022/Oct/45nvdMailing ListThird Party Advisory
- lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.htmlnvdMailing ListVendor Advisory
- support.apple.com/kb/HT213443nvdThird Party Advisory
- support.apple.com/kb/HT213444nvdThird Party Advisory
- support.apple.com/kb/HT213488nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/12/msg00004.htmlnvd
- security.netapp.com/advisory/ntap-20230427-0012/nvd
News mentions
0No linked articles in our index yet.