NetHack command line parsing of options starting with -de and -i is subject to a buffer overflow
Vulnerability Description
In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options. Users should upgrade to NetHack 3.6.5.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5209
Credits & Attribution
No credits recorded in the NVD database.
References
More from NetHack
View All →Affected Vendor
NetHack
View all reports →