CVE-2020-5254: NetHack hilite_status parsing privilege escalation
Published Mar 10, 2020
·Updated
In NetHack before 3.6.6, some out-of-bound values for the hilitestatus option can be exploited. NetHack 3.6.6 resolves this issue.
Affected Software
1 affected component
NetHack NetHack>=3.6.1<3.6.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nethackto a version that resolves this vulnerability.Fixed in 3.6.6
Event History
Mar 10, 2020
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-5254?
CVE-2020-5254 has a medium severity rating due to its potential for exploitation through out-of-bounds values.
2
How do I fix CVE-2020-5254?
To fix CVE-2020-5254, upgrade to NetHack version 3.6.6 or later.
3
What software versions are affected by CVE-2020-5254?
CVE-2020-5254 affects NetHack versions from 3.6.1 to 3.6.5.
4
Does CVE-2020-5254 affect all versions of NetHack?
No, CVE-2020-5254 only affects versions prior to 3.6.6.
5
What type of vulnerability is CVE-2020-5254?
CVE-2020-5254 is an out-of-bounds write vulnerability that can be exploited through the hilite_status option.