CVE-2025-6141 is a stack-based buffer overflow vulnerability in GNU ncurses versions up to 6.5-20250322, specifically within the postprocess_termcap function in tinfo/parse_entry.c. This vulnerability has a low severity CVSS score of 3.3, requiring local access and low privileges for exploitation, resulting in a low impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it has received limited media coverage. Upgrading to ncurses version 6.5-20250329 remediates this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| GNU | Ncurses | 6.5-20250322CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.