Описание
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ncurses | fixed | 6.6+20251231-1 | package | |
| ncurses | no-dsa | trixie | package | |
| ncurses | no-dsa | bookworm | package | |
| ncurses | postponed | bullseye | package |
Примечания
https://github.com/Cao-Wuhui/CVE-2025-69720
https://invisible-island.net/ncurses/NEWS.html#index-t20251213
EPSS
Процентиль: 6%
0.00021
Низкий
Связанные уязвимости
CVSS3: 7.3
ubuntu
15 дней назад
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
CVSS3: 7.3
redhat
15 дней назад
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
CVSS3: 7.3
nvd
15 дней назад
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
CVSS3: 9.8
github
15 дней назад
ncurses v6.5 and v6.4 are vulnerable to Buffer Overflow in progs/infocmp.c, function analyze_string().
EPSS
Процентиль: 6%
0.00021
Низкий