Home
HIGH: 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:LDefault status
unaffected
Any version before 6.5-20251213
affected
Description
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
Problem types
CWE-121 Stack-based Buffer Overflow
Product status
Any version before 6.5-20251213
References
cert-portal.siemens.com/productcert/html/ssa-253495.html
marc.info/?l=ncurses-bug&m=176539968328570&w=2
marc.info/?l=ncurses-bug&m=176540731801330&w=2
marc.info/?l=ncurses-bug&m=176545557728083&w=2
github.com/Cao-Wuhui/CVE-2025-69720
invisible-island.net/archives/ncurses/6.5/