S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().
The vulnerability results from improper buffer handling in the fixup_tgetstr() function of the S-Lang library. Lack of proper buffer boundary validation (classic buffer overflow, CWE-120) enables triggering a segmentation fault. An attacker can remotely cause an application using this library to crash, and depending on the context, potentially gain unauthorized access to data in memory.
An attacker can cause unauthorized data access (confidentiality breach) and trigger an application crash resulting in denial of service (availability breach). The attack vector is network-based and does not require authentication or user interaction.
Apply patches available from the vendor according to the references provided. It is recommended to monitor the slang-users mailing list (lists.jedsoft.org) and update to a version where the bug has been fixed. Until the fix is implemented, consider restricting network access to applications using the S-Lang library.
Jedsoft S-Lang version 2.3.2. Other versions may also be vulnerable – check the vendor references.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HJedsoft S Lang
APPJedsoft2.3.2