CVE-2025-6141
GNU ncurses parse_entry.c postprocess_termcap stack-based overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.
In GNU ncurses bis 6.5-20250322 wurde eine problematische Schwachstelle gefunden. Es geht um die Funktion postprocess_termcap der Datei tinfo/parse_entry.c. Dank Manipulation mit unbekannten Daten kann eine stack-based buffer overflow-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs hat dabei lokal zu erfolgen. Ein Aktualisieren auf die Version 6.5-20250329 vermag dieses Problem zu lösen. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-06-15 CVE Reserved
- 2025-06-16 CVE Published
- 2025-06-17 CVE Updated
- 2025-06-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-121: Stack-based Buffer Overflow
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://invisible-island.net/ncurses/NEWS.html#index-t20250329 | Related | |
https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html | Related | |
https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html | Related | |
https://vuldb.com/?id.312610 | Technical Description | |
https://vuldb.com/?submit.593000 | Third Party Advisory | |
https://www.gnu.org | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html | 2025-06-16 |
URL | Date | SRC |
---|