Learn about CVE-2020-5211 affecting NetHack before 3.6.5. Discover impact, vulnerability details, and mitigation steps to prevent buffer overflow risks.
NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflow.
Understanding CVE-2020-5211
In NetHack before 3.6.5, an invalid extended command in the AUTOCOMPLETE configuration file option can lead to a buffer overflow, potentially causing a crash or enabling remote code execution/privilege escalation.
What is CVE-2020-5211?
NetHack before version 3.6.5 is vulnerable to a buffer overflow due to an invalid extended command in the AUTOCOMPLETE configuration file option.
The vulnerability impacts systems with NetHack installed suid/sgid and shared systems allowing user-uploaded configuration files.