ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable. ========Wind River Notice======== Customer can configure with --disable-root-environ. With this, ncurses will not be affected by CVE-2023-29491.