Close Menu
NotesleuNotesleu
    Facebook X (Twitter) Instagram
    Tuesday, February 10
    Facebook X (Twitter) Instagram
    NotesleuNotesleu
    • Home
    • General News
    • Cyber Attacks
    • Threats
    • Vulnerabilities
    • Cybersecurity
    • Contact Us
    • More
    NotesleuNotesleu
    Home»Vulnerabilities»Microsoft Detects Vulnerabilities in ncurses Library Impacting Linux and macOS Devices
    Vulnerabilities

    Microsoft Detects Vulnerabilities in ncurses Library Impacting Linux and macOS Devices

    By securnerd2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Follow Us
    Google News

    Microsoft’s investigative team has identified several memory corruption vulnerabilities within the ncurses programming library. These vulnerabilities pose a potential risk to Linux and macOS systems, allowing hackers the opportunity to execute harmful code.

    The research team, composed of Jonathan Bar Or, Emanuele Cozzi, and Michael Pearse from Microsoft Threat Intelligence, detailed in their latest report how threat actors could use environment variable manipulation to take advantage of these flaws. The objective? To increase privileges and execute commands in the context of the affected application or initiate other malevolent tasks.

    Designated as CVE-2023-29491 and having a CVSS score of 7.8, these vulnerabilities have been rectified as of April 2023. Microsoft has also collaborated with Apple to tackle macOS-specific challenges arising from these vulnerabilities.

    For clarity, environment variables are customizable values accessible by multiple software applications on a device. Tweaking these can sometimes lead apps to execute actions they aren’t typically authorized to do.

    During Microsoft’s in-depth code review and testing, it was determined that the ncurses library looks for a range of environment variables. One such variable is TERMINFO. Threat actors can tamper with it, combining this with the detected vulnerabilities, to escalate privileges. TERMINFO serves as a database, allowing software to interface with display terminals in a universal manner.

    A breakdown of the vulnerabilities includes a stack data disclosure, confusion over parameterized string types, minor counting errors, and problems related to terminfo database file interpretation, such as a heap boundary violation and a denial-of-service using invalidated strings.

    The team emphasized, “While these vulnerabilities could provide pathways for hackers to escalate their access and execute commands in a given program’s environment, achieving this requires a layered attack approach.”

    They further explained that to actually elevate access, a combination of vulnerabilities might be essential. This could mean utilizing the stack data disclosure to acquire arbitrary reading capabilities, coupled with exploiting the heap boundary violation to gain write capabilities.

    Found this news interesting? Follow us on Twitter  and Telegram to read more exclusive content we post.

    Post Views: 97

    Related Posts

    • Laugh, Cry and Learn Within Virtual Reality
    • Ukrainian Authorities Detect Russian Hacker Campaign Seeking Evidence of War Crimes
    • Lazarus Hackers Exploit Microsoft IIS Servers for Malware Dissemination
    • Indian National Pleads Guilty to $37 Million Cryptocurrency Theft Scheme
    Follow on Google News
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Add A Comment
    Leave A Reply Cancel Reply

    Recent Post

    Complete HTML Handwritten Notes

    July 22, 2024

    Complete C++ Handwritten Notes From Basic to Advanced

    July 21, 2024

    Complete Python Ebook From Basic To Advanced

    July 20, 2024

    Top 7 Open-Source LLMs for 2024 and Their Uses

    July 18, 2024
    About Us
    About Us

    We're your premier source for the latest in AI, cybersecurity, science, and technology. Dedicated to providing clear, thorough, and accurate information, our team brings you insights into the innovations that shape tomorrow. Let's navigate the future together."

    Latest

    Complete HTML Handwritten Notes

    July 22, 2024

    Complete C++ Handwritten Notes From Basic to Advanced

    July 21, 2024

    Complete Python Ebook From Basic To Advanced

    July 20, 2024
    Popular Post

    Microsoft Enhances Windows 11 Security with Kerberos Authentication Over NTLM Protocol

    October 15, 202318 Views

    New JavaScript Malware Targeted 50,000+ Users at Dozens of Banks Worldwide

    December 21, 202337 Views

    Malicious Ads Exploit macOS Users, Unleashing Stealer Malware

    April 1, 202418 Views
    • Contact Us
    • About US
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 Notesleu. Designed by NIM.

    Type above and press Enter to search. Press Esc to cancel.