Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2025-69720 — Avviso per CVE-2025-69720: buffer overflow basato su stack in GNU ncurses infocmp (CWE-121) | Kitploit
Strumenti/GitHubGitHub/cao-wuhui/cve-2025-69720
Analisi StaticaAnalisi delle VulnerabilitàExploitFuzzingAnalisi di BinariApprendimento e Formazione
GitHubcao-wuhui/cve-2025-69720

CVE-2025-69720

Avviso per CVE-2025-69720: buffer overflow basato su stack in GNU ncurses infocmp (CWE-121)

Vedi Repository
2506 mesi faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Sito web
Condividi

CVE-2025-69720: ncurses infocmp -i Stack Buffer Overflow (CWE-121)

Segnalato da: Yixuan Cao (Shenzhen University), [email protected]

Ambiente

  • Host: openEuler 22.03 LTS (Linux aarch64)
  • Toolchain: system clang 12.0.1 + AddressSanitizer
  • Sorgente: ncurses-6.4 e ncurses-6.5 (prima della patch 20251213)

Riepilogo

infocmp -i invoca analyze_string() (progs/infocmp.c) per ispezionare le sequenze CSI trovate in una voce terminfo. La routine copia la sottostringa candidata in un buffer stack di dimensione fissa (buf2, 4096 byte). Poiché len = strlen(cp) non viene controllato rispetto a 4096, una lista di parametri CSI maliziosamente lunga (ad es., sgr=\E[1234567;…;m con ~800 parametri) causa un overflow di buf2, provocando uno stack smash. Lo stesso PoC si riproduce su 6.4 e su 6.5 prima della patch 20251213 (vedi output ASan sotto). Le versioni precedenti alla 6.4 non sono state testate.

La news di ncurses (2025/12/13) ha confermato e corretto il bug, ed è disponibile una patch ufficiale.

Impatto

  • Eseguire infocmp -i su una voce terminfo appositamente creata può causare un crash dello strumento (stack-buffer-overflow), cioè un denial of service locale per quella invocazione.
  • L'overflow si verifica in progs/infocmp.c (analyze_string) quando len = strlen(cp) viene usato per copiare in buf2[MAX_TERMINFO_LENGTH] (4096) senza controllare len, ed è seguito da buf2[len] = '\0'.
  • L'opzione -i è un percorso di analisi specializzato per le capacità relative a init/reset (is1/is2/is3/rs1/rs2/rs3/smcup/rmcup/smkx/rmkx); non influenza l'uso comune di infocmp senza -i.
  • Corretto in: ncurses 6.5 con patch 20251213 (ncurses-6.5-20251213.patch.gz).

Passi per la riproduzione (prendere ncurses-6.4 come esempio)

  1. Preparare e compilare il codice sorgente di ncurses-6.4 con ASan:
    # Scaricare ed estrarre il codice sorgente di ncurses-6.4
    # (si suppone che si trovi in ~/ncurses-6.4, cioè /home/<utente>/ncurses-6.4)
    cd ~
    wget https://invisible-mirror.net/archives/ncurses/ncurses-6.4.tar.gz
    tar xvf ncurses-6.4.tar.gz
    cd ncurses-6.4
    
    # Configurare con ASan
    CC=clang \
    CFLAGS='-O1 -g -fsanitize=address' \
    LDFLAGS='-fsanitize=address' \
    ./configure --enable-widec   # mantenere il supporto wide-char in modo che il lungo SGR sopravviva
    
    # Compilare infocmp/tic/ecc.
    make -j$(nproc)
    
  2. Compilare il sorgente terminfo del PoC (supponendo che il file sia in ~/evil_sgr.ti) in un database temporaneo:
    ~/ncurses-6.4/progs/tic -x -o /tmp/evilti ~/evil_sgr.ti
    
  3. Attivare l'overflow con infocmp abilitato con ASan:
    TERMINFO=/tmp/evilti ~/ncurses-6.4/progs/infocmp -i evil_sgr
    
    (Per 6.5, usare i percorsi corrispondenti ~/ncurses-6.5/progs/....)

Output ASan

Per ncurses-6.4:

[yixuan@Taishan200 ~]$ TERMINFO=/tmp/evilti ~/ncurses-6.4/progs/infocmp -i evil_sgr
=================================================================
==3848299==ERROR: AddressSanitizer: stack-buffer-overflow on address 0xffffcfa5e240 at pc 0x000000443344 bp 0xffffcfa5c9b0 sp 0xffffcfa5ca08
WRITE of size 6402 at 0xffffcfa5e240 thread T0
    #0 0x443340 in strncpy (/home/yixuan/ncurses-6.4/progs/infocmp+0x443340)
    #1 0x4eee78 in analyze_string /home/yixuan/ncurses-6.4/progs/../progs/infocmp.c:850:3
    #2 0x4ecebc in main /home/yixuan/ncurses-6.4/progs/../progs/infocmp.c:1881:6
    #3 0xffffab9d0ffc  (/usr/lib64/libc.so.6+0x2affc)
    #4 0xffffab9d10d4 in __libc_start_main (/usr/lib64/libc.so.6+0x2b0d4)
    #5 0x42936c in _start (/home/yixuan/ncurses-6.4/progs/infocmp+0x42936c)

Address 0xffffcfa5e240 is located in stack of thread T0 at offset 4128 in frame
    #0 0x4eebe0 in analyze_string /home/yixuan/ncurses-6.4/progs/../progs/infocmp.c:818

  This frame has 2 object(s):
    [32, 4128) 'buf2' (line 819)
    [4256, 8352) 'buf3' (line 834) <== Memory access at offset 4128 partially underflows this variable
HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork
      (longjmp and C++ exceptions *are* supported)
SUMMARY: AddressSanitizer: stack-buffer-overflow (/home/yixuan/ncurses-6.4/progs/infocmp+0x443340) in strncpy
Shadow bytes around the buggy address:
  0x200ff9f4bbf0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
=>0x200ff9f4bc40: 00 00 00 00 00 00 00 00[f2]f2 f2 f2 f2 f2 f2 f2
  0x200ff9f4bc50: f2 f2 f2 f2 f2 f2 f2 f2 00 00 00 00 00 00 00 00
  0x200ff9f4bc60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07 
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
  Shadow gap:              cc
==3848299==ABORTING

E per ncurses-6.5:

[yixuan@Taishan200 ~]$  TERMINFO=/tmp/evilti ~/ncurses-6.5/progs/infocmp -i evil_sgr
=================================================================
==3863888==ERROR: AddressSanitizer: stack-buffer-overflow on address 0xfffff7af5380 at pc 0x000000443544 bp 0xfffff7af3af0 sp 0xfffff7af3b48
WRITE of size 6402 at 0xfffff7af5380 thread T0
    #0 0x443540 in strncpy (/home/yixuan/ncurses-6.5/progs/infocmp+0x443540)
    #1 0x4ef094 in analyze_string /home/yixuan/ncurses-6.5/progs/../progs/infocmp.c:874:3
    #2 0x4ed0d8 in main /home/yixuan/ncurses-6.5/progs/../progs/infocmp.c:1913:6
    #3 0xffff811baffc  (/usr/lib64/libc.so.6+0x2affc)
    #4 0xffff811bb0d4 in __libc_start_main (/usr/lib64/libc.so.6+0x2b0d4)
    #5 0x42956c in _start (/home/yixuan/ncurses-6.5/progs/infocmp+0x42956c)

Address 0xfffff7af5380 is located in stack of thread T0 at offset 4128 in frame
    #0 0x4eedfc in analyze_string /home/yixuan/ncurses-6.5/progs/../progs/infocmp.c:842
Scarica lo strumento