Skip to content

NetHack 3.4.3 privilege escalation

High
nhkeni published GHSA-2c7p-3fj4-223m Mar 8, 2020

Package

No package listed

Affected versions

<=3.4.3

Patched versions

>=3.6.0

Description

Impact

Malicious use of escaping of characters in the configuration file (usually .nethackrc) can be exploited.

Patches

This bug was patched in NetHack 3.6.0 commit 612755b; as 3.4.3 is no longer supported this CVE is informational only for NetHack but may be of concern to NetHack variants that are still based on the 3.4.3 code.

Workarounds

None.

References

Additional information, if any, will be made available at https://nethack.org/security.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2020-5253

Weaknesses

No CWEs