CVE-2025-69720
March 19, 2026
The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
Affected Packages
git://ncurses.scripts.mit.edu/ncurses.git (SCM_GIT):
Affected version(s) >=v6.4 <v6.6Fix Suggestion:
Update to version v6.6Related ResourcesĀ (6)
Do you need more information?
Contact UsCVSS v3
Base Score:
7.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH
Weakness Type (CWE)
EPSS
Base Score:
0.02