CVE-2020-5209

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
28/01/2020
Last modified:
03/02/2020

Description

In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options. Users should upgrade to NetHack 3.6.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nethack:nethack:*:*:*:*:*:*:*:* 3.6.5 (excluding)