Launchpad.net

CVE 2017-10685

In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.

See the CVE page on Mitre.org for more details.