NA

CVE-2023-24809

Published: 17/02/2023 Updated: 28/02/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal input to the "C" (call) command can cause a buffer overflow and crash the NetHack process. This vulnerability may be a security issue for systems that have NetHack installed suid/sgid and for shared systems. For all systems, it may result in a process crash. This issue is resolved in NetHack 3.6.7. There are no known workarounds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nethack nethack

Vendor Advisories

Debian Bug report logs - #1031869 nethack: CVE-2023-24809 Package: src:nethack; Maintainer for src:nethack is Debian Games Team <pkg-games-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 24 Feb 2023 16:03:01 UTC Severity: important Tags: security, upstream Reply or su ...