CVE-2019-19905

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
19/12/2019
Last modified:
27/12/2019

Description

NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nethack:nethack:*:*:*:*:*:*:*:* 3.6.0 (including) 3.6.4 (excluding)