Improper Privilege Management in NetHack - CVE-2020-5253
Published: March 10, 2020 / Updated: August 8, 2020
Vulnerability identifier: #VU34796
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-5253
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: The NetHack DevTeam
Affected software:
NetHack
NetHack
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.
How to mitigate CVE-2020-5253
Install update from vendor's website.