Severity: High
Affected versions: 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.6.4
First Patched Version: 3.6.5
Git commit(s): a842fda44c612cd9a126c3039a575da92c6ee0f4
Basic Information:
Extremely long value for the MENUCOLOR configuration file option can cause a
buffer overflow resulting in a crash or remote code execution/privilege
escalation.
This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files.
All users are urged to upgrade to NetHack 3.6.5 as soon as possible.
Additional information related to this advisory, if any, will be made available at https://nethack.org/security.
Timeline:
27-Jan-2020 NetHack 3.6.5 released with fix.
12-Jan-2020 Bug reported.
NetHack is Copyright 1985-2023 by Stichting Mathematisch Centrum
and M. Stephenson. See
our license for details.
This site is Copyright 1999-2023 by Kenneth Lorber, Kensington, Maryland.