#VU34796 Improper Privilege Management in NetHack - CVE-2020-5253

 

#VU34796 Improper Privilege Management in NetHack - CVE-2020-5253

Published: March 10, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34796
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-5253
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
NetHack
Software vendor:
The NetHack DevTeam

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.


Remediation

Install update from vendor's website.

External links