- Reported
-
- Issued
-
- Package
-
ncurses
(crates.io)
- Type
-
INFO
Unsound
- Categories
-
- Keywords
-
#memory-safety
#soundness
- References
-
- Patched
-
no patched versions
- Affected Functions
- Version
ncurses::inchnstr
-
ncurses::inchstr
-
ncurses::innstr
-
ncurses::mvwinchnstr
-
ncurses::mvwinchstr
-
ncurses::mvwinnstr
-
ncurses::winchnstr
-
ncurses::winchstr
-
ncurses::winnstr
-
ncurses::winstr
-
Description
Multiple string reading functions expose uninitialized memory by setting length to capacity when no null terminator is found.
This allows reading uninitialized memory which may contain sensitive data from previous allocations.
The ncurses-rs repository is archived and unmaintained.
Advisory available under CC0-1.0
license.