CVE-2020-5253: Privilege escalation in NetHack
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nethackto a version that resolves this vulnerability.Fixed in 3.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5253?
CVE-2020-5253 has been classified as having a moderate severity due to the potential for configuration file exploitation.
How do I fix CVE-2020-5253?
The fix for CVE-2020-5253 is to upgrade to NetHack version 3.6.0 or later immediately.
What vulnerabilities does CVE-2020-5253 address?
CVE-2020-5253 addresses a vulnerability related to the manipulation of escape characters in the NetHack configuration file.
Who is affected by CVE-2020-5253?
Users running versions of NetHack prior to 3.6.0 are affected by CVE-2020-5253.
Is CVE-2020-5253 publicly disclosed?
Yes, CVE-2020-5253 is a publicly disclosed vulnerability with available patches.