There are 2 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2025-6141:
(needs triaging)
A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.
- CVE-2023-50495:
(needs triaging)
NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().
You can find information about how to handle these issues in the security team's documentation.