Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2023-24809
Disclosure Date: February 17, 2023 (last updated October 08, 2023)
NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal input to the "C" (call) command can cause a buffer overflow and crash the NetHack process. This vulnerability may be a security issue for systems that have NetHack installed suid/sgid and for shared systems. For all systems, it may result in a process crash. This issue is resolved in NetHack 3.6.7. There are no known workarounds.
0
Attacker Value
Unknown
CVE-2020-5253
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.
0
Attacker Value
Unknown
CVE-2020-5254
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue.
0
Attacker Value
Unknown
NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflow
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.
0
Attacker Value
Unknown
NetHack command line -w option parsing is subject to a buffer overflow
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options. Users should upgrade to NetHack 3.6.5.
0
Attacker Value
Unknown
NetHack MENUCOLOR configuration file option is subject to a buffer overflow
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.
0
Attacker Value
Unknown
NetHack SYMBOL configuration file option is subject to a buffer overflow
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.
0
Attacker Value
Unknown
NetHack error recovery after syntax error in configuration file is subject to a…
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.
0
Attacker Value
Unknown
NetHack command line parsing of options starting with -de and -i is subject to …
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options. Users should upgrade to NetHack 3.6.5.
0
Attacker Value
Unknown
CVE-2019-19905
Disclosure Date: December 19, 2019 (last updated November 27, 2024)
NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.
0