CVE-2025-6141
A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.
System detected CVE-2025-6141 with a risk of 1.2
System detected CVE-2025-6141 with a risk of 1.2
- S
Sebastian Kawelke updated the risk assessment from 1.2 to 1.85
Confidentiality Requirement updated: high -> low, Availability Requirement updated: low -> high
- S
Sebastian Kawelke updated the risk assessment from 1.2 to 1.85
Confidentiality Requirement updated: high -> low, Availability Requirement updated: low -> high
System updated the risk assessment from 1.85 to 0.55
System recalculated raw risk assessment
System updated the risk assessment from 1.85 to 0.55
System recalculated raw risk assessment
System fixed CVE-2025-6141
System fixed CVE-2025-6141
System detected CVE-2025-6141 with a risk of 0.55
Add a comment
Affected component
debian/ncurses