Описание
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
A flaw was found in ncurses. This vulnerability, a buffer overflow, exists within the analyze_string() function. An attacker could potentially exploit this to execute unauthorized code on the affected system, which might lead to a denial of service in the affected application, the corruption of data, or sensitive information being revealed to an attacker.
Отчет
This Moderate impact vulnerability in ncurses affects Red Hat Enterprise Linux 10.0.z and 10.1.z. A buffer overflow in the analyze_string() function, exploitable through the infocmp utility, could lead to arbitrary code execution. Red Hat Enterprise Linux 6-ELS, 7-ELS, 8.x, 9.x, and OpenShift Container Platform are not affected as the vulnerable code is not present in these versions. Exploitation of this vulnerability requires that an affected application processes malicious data; this requires either user interaction or privileges on an affected system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ncurses | Not affected | ||
| Red Hat Enterprise Linux 7 | ncurses | Not affected | ||
| Red Hat Enterprise Linux 8 | ncurses | Not affected | ||
| Red Hat Enterprise Linux 9 | ncurses | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected | ||
| Red Hat Enterprise Linux 10 | ncurses | Fixed | RHSA-2026:5913 | 26.03.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | ncurses | Fixed | RHSA-2026:26357 | 16.06.2026 |
| Red Hat Hardened Images | ncurses-main-6.6-1.1.hum1 | Fixed | RHSA-2026:7263 | 09.04.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ...
EPSS
7.8 High
CVSS3