Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-69720

Опубликовано: 19 мар. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

A flaw was found in ncurses. This vulnerability, a buffer overflow, exists within the analyze_string() function. An attacker could potentially exploit this to execute unauthorized code on the affected system, which might lead to a denial of service in the affected application, the corruption of data, or sensitive information being revealed to an attacker.

Отчет

This Moderate impact vulnerability in ncurses affects Red Hat Enterprise Linux 10.0.z and 10.1.z. A buffer overflow in the analyze_string() function, exploitable through the infocmp utility, could lead to arbitrary code execution. Red Hat Enterprise Linux 6-ELS, 7-ELS, 8.x, 9.x, and OpenShift Container Platform are not affected as the vulnerable code is not present in these versions. Exploitation of this vulnerability requires that an affected application processes malicious data; this requires either user interaction or privileges on an affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ncursesNot affected
Red Hat Enterprise Linux 7ncursesNot affected
Red Hat Enterprise Linux 8ncursesNot affected
Red Hat Enterprise Linux 9ncursesNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Enterprise Linux 10ncursesFixedRHSA-2026:591326.03.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportncursesFixedRHSA-2026:2635716.06.2026
Red Hat Hardened Imagesncurses-main-6.6-1.1.hum1FixedRHSA-2026:726309.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2449037ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.

EPSS

Процентиль: 37%
0.00447
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

CVSS3: 7.3
nvd
4 месяца назад

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

CVSS3: 9.8
msrc
4 месяца назад

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

CVSS3: 7.3
debian
4 месяца назад

The infocmp command-line tool in ncurses before 6.5-20251213 has a sta ...

suse-cvrf
около 1 месяца назад

Security update for ncurses

EPSS

Процентиль: 37%
0.00447
Низкий

7.8 High

CVSS3