Analyst readout for executives and security teams
Plain-English summary
This is an old local privilege-escalation issue in ncurses. On systems with affected packages, a person who already has local access could potentially use a buffer overflow to gain higher privileges. It is not described as remote compromise in the provided sources.
Executive priority
Prioritize as legacy risk management, not an internet-wide emergency. Escalate if affected packages exist on shared shell, hosting, build, or operational systems where local users should not gain administrative privileges.
Technical view
The CVE describes a buffer overflow in ncurses 5.0 and the Red Hat ncurses4 compatibility package, related to physical cursor movement and scrolling routines. The stated impact is local privilege gain. The bundle does not include CVSS, CWE, or exact vulnerable package build ranges.
Likely exposure
Likely limited to very old Linux systems retaining ncurses 5.0 or the referenced ncurses4 compatibility package. Modern supported distributions are unlikely to be exposed, but legacy servers, embedded systems, recovery images, and unsupported build environments should be checked.
Exploitation context
The provided sources support local privilege escalation only. CISA KEV is false in the bundle, and no cited source here establishes active exploitation. Risk is highest where untrusted users have shell access on affected legacy hosts.
Researcher notes
Evidence is sparse in the provided bundle. The key verified facts are buffer overflow, ncurses 5.0 or Red Hat ncurses4 compatibility package, local privilege gain, and vendor advisories from Debian and Red Hat. No exploit mechanics or active exploitation evidence is included.
Mitigation direction
- Check Debian and Red Hat advisories for corrected package guidance.
- Inventory systems for ncurses 5.0 and ncurses4 compatibility packages.
- Upgrade or remove affected legacy packages according to vendor guidance.
- Restrict local shell access on systems that cannot be immediately remediated.
Validation and detection
- Confirm installed ncurses package names and versions on legacy Linux hosts.
- Review asset inventory for unsupported Red Hat or Debian-era systems.
- Check whether untrusted users can log in locally or via shell.
- Document remediation status against the referenced vendor advisories.
Based on public source material and reviewed before publication.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2002-0062 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- 2116CVE reference · vdb-entry, x_refsource_BID
- DSA-113CVE reference · vendor-advisory, x_refsource_DEBIAN
- RHSA-2002:020CVE reference · vendor-advisory, x_refsource_REDHAT
- gnu-ncurses-window-bo(8222)CVE reference · vdb-entry, x_refsource_XF
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
