Back to Database
Status published
Low
CVE-2020-5254
NetHack hilite_status parsing privilege escalation
Vulnerability Description
In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5254
Credits & Attribution
No credits recorded in the NVD database.
More from NetHack
View All →CVE-2023-24809
NetHack Call command buffer overflow
Medium
5.5
CVE-2020-5253
Privilege escalation in NetHack
Low
3.9
CVE-2020-5214
NetHack error recovery after syntax error in configuration file is subject to a buffer overflow
Medium
5
CVE-2020-5213
NetHack SYMBOL configuration file option is subject to a buffer overflow
Medium
5
CVE-2020-5212
NetHack MENUCOLOR configuration file option is subject to a buffer overflow
Medium
5
Affected Vendor
NetHack
View all reports →Affected Software
NetHack
Vulnerable Versions:
< 3.6.6
Timeline
Official Publish:
March 10th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N