There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack. https://nvd.nist.gov/vuln/detail/CVE-2017-13729