ncurses v6.5 and v6.4 are vulnerable to Buffer Overflow in progs/infocmp.c, function analyze_string().
History

Sat, 21 Mar 2026 05:30:00 +0000

Type Values Removed Values Added
Title ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.
Weaknesses CWE-120
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

threat_severity

Moderate


Fri, 20 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Gnu
Gnu ncurses
Vendors & Products Gnu
Gnu ncurses

Thu, 19 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
Description ncurses v6.5 and v6.4 are vulnerable to Buffer Overflow in progs/infocmp.c, function analyze_string().
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-03-19T00:00:00.000Z

Updated: 2026-03-19T14:52:32.368Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-69720

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-19T15:16:21.293

Modified: 2026-03-20T13:39:46.493

Link: CVE-2025-69720

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-03-19T00:00:00Z

Links: CVE-2025-69720 - Bugzilla