CVE-2017-10684 (https://nvd.nist.gov/vuln/detail/CVE-2017-10684) In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack. References: https://bugzilla.redhat.com/show_bug.cgi?id=1464687 https://bugzilla.redhat.com/show_bug.cgi?id=1473302 Upstream patch: https://lists.gnu.org/archive/html/bug-ncurses/2017-07/msg00001.html
CVE-2017-10685 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10685): In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
This issue was resolved and addressed in GLSA 201804-13 at https://security.gentoo.org/glsa/201804-13 by GLSA coordinator Aaron Bauman (b-man).