A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.
CVSS Details
- CVSS 4.0 Base Score: 4.8 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | Jun 18, 2025 | Jun 16, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade ncurses-baseUpgrade ncursesUpgrade ncurses-libs | Nov 12, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade ncursesUpgrade ncurses-baseUpgrade ncurses-libs | Oct 14, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade ncurses-libsUpgrade ncursesUpgrade ncurses-base | Nov 12, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade ncurses-libsUpgrade ncursesUpgrade ncurses-base | Oct 24, 2025 | Oct 10, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 17, 2025 | Jun 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub