A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.
CVSS Details
- CVSS 4.0 Base Score: 4.8 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | Jun 18, 2025 | Jun 16, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade ncurses-baseUpgrade ncursesUpgrade ncurses-libs | Nov 12, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade ncursesUpgrade ncurses-baseUpgrade ncurses-libs | Oct 14, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade ncurses-baseUpgrade ncursesUpgrade ncurses-libs | Nov 12, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade ncurses-baseUpgrade ncurses-libsUpgrade ncurses | Oct 24, 2025 | Oct 10, 2025 |
| Ubuntu | — | Upgrade ncurses-bin (Ubuntu Pro)Upgrade libncurses5Upgrade libncurses5 (Ubuntu Pro)Upgrade libncurses6Upgrade libtinfo5 (Ubuntu Pro)Upgrade libtinfo5Upgrade libtinfo6 (Ubuntu Pro)Upgrade ncurses-binUpgrade libncurses6 (Ubuntu Pro)Upgrade libtinfo6 | Sep 2, 2026 | Sep 1, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 17, 2025 | Jun 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub