PT-2025-25593 · Gnu+1 · Ncurses+1

·

CVE-2025-6141

·

Published

2025-06-16

·

Updated

2026-09-01

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GNU ncurses versions up to 6.5-20250322
Description A stack-based buffer overflow issue has been identified, affecting the postprocess termcap function in the tinfo/parse entry.c file. This issue can be exploited locally.
Recommendations For GNU ncurses versions up to 6.5-20250322, upgrade to version 6.5-20250329 to address this issue. As a temporary workaround, consider restricting access to the postprocess termcap function until the upgrade is applied.

Fix

Buffer Overflow

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-64139
CVE-2025-6141
ECHO-D3C9-C3E9-90E8
JLSEC-2026-454
OESA-2025-1851
USN-8709-1

Affected Products

Debian
Ncurses