There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack. https://nvd.nist.gov/vuln/detail/CVE-2017-13730