Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # nethack-3.4.3-6.1 on GA media Announcement ID: openSUSE-SU-2025:14898-1 Rating: moderate Cross-References: * CVE-2020-5253 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the nethack-3.4.3-6.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * nethack 3.4.3-6.1 ## References: * https://www.suse.com/security/cve/CVE-2020-5253.html . Install the latest openSUSE security update for nethack-3.4.3-6.1 to address a moderate vulnerability impacting your system.. update, solves, vulnerability, installed, nethack-3, media, announ. . LinuxSecurity.com Team
Updated nethack packages fix security vulnerabilities: NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to . MGASA-2021-0077 - Updated nethack packages fix security vulnerabilities Publication date: 10 Feb 2021 URL: https://advisories.mageia.org/MGASA-2021-0077.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-19905, CVE-2020-5209, CVE-2020-5210, CVE-2020-5211, CVE-2020-5212, CVE-2020-5213, CVE-2020-5214, CVE-2020-5254 Updated nethack packages fix security vulnerabilities: NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files (CVE-2019-19905). In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options (CVE-2020-5209). In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options (CVE-2020-5210). In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files (CVE-2020-5211). In NetHack before 3.6.5, anextremely long value for the MENUCOLOR configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files (CVE-2020-5212). In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files (CVE-2020-5213). In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files (CVE-2020-5214). In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited (CVE-2020-5254). The nethack package has been updated to version 3.6.6, fixing these issues and other bugs. See the upstream release notes for details. References: - https://bugs.mageia.org/show_bug.cgi?id=26228 - https://nethack.org/v362/release.html - https://nethack.org/v363/release.html - https://nethack.org/v364/release.html - https://nethack.org/v365/release.html - https://nethack.org/v366/release.html - https://www.nethack.org/security/CVE-2019-19905.html - https://www.nethack.org/security/CVE-2020-5209.html - https://www.nethack.org/security/CVE-2020-5210.html - https://www.nethack.org/security/CVE-2020-5211.html - https://www.nethack.org/security/CVE-2020-5212.html - https://www.nethack.org/security/CVE-2020-5213.html - https://www.nethack.org/security/CVE-2020-5214.html - https://www.nethack.org/security/CVE-2020-5254.html - https://www.cve.org/CVERecord?id=CVE-2019-19905 -https://www.cve.org/CVERecord?id=CVE-2020-5209 - https://www.cve.org/CVERecord?id=CVE-2020-5210 - https://www.cve.org/CVERecord?id=CVE-2020-5211 - https://www.cve.org/CVERecord?id=CVE-2020-5212 - https://www.cve.org/CVERecord?id=CVE-2020-5213 - https://www.cve.org/CVERecord?id=CVE-2020-5214 - https://www.cve.org/CVERecord?id=CVE-2020-5254 SRPMS: - 7/core/nethack-3.6.6-1.mga7 . The revamped NetHack component resolves critical memory corruption vulnerabilities in Mageia, significantly boosting system defenses.. NetHack Update, Mageia Security, Buffer Overflow Patch. . Severity: Critical. LinuxSecurity.com Team
Update to NetHack 3.6.4 - fixes security issue with privilege escalation: http://nethack.org/security/index.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-79b80b66d9 2020-01-03 20:35:14.417550 --------------------------------------------------------------------------------Name : nethack Product : Fedora 30 Version : 3.6.4 Release : 1.fc30 URL : https://nethack.org Summary : A rogue-like single player dungeon exploration game Description : NetHack is a single player dungeon exploration game that runs on a wide variety of computer systems, with a variety of graphical and text interfaces all using the same game engine. Unlike many other Dungeons & Dragons-inspired games, the emphasis in NetHack is on discovering the detail of the dungeon and not simply killing everything in sight - in fact, killing everything in sight is a good way to die quickly. Each game presents a different landscape - the random number generator provides an essentially unlimited number of variations of the dungeon and its denizens to be discovered by the player in one of a number of characters: you can pick your race, your role, and your gender. --------------------------------------------------------------------------------Update Information: Update to NetHack 3.6.4 - fixes security issue with privilege escalation: http://nethack.org/security/index.html --------------------------------------------------------------------------------ChangeLog: * Thu Dec 19 2019 Ron Olson - 3.6.4-1 - Update to NetHack 3.6.4 * Mon Dec 9 2019 Ron Olson - 3.6.3-1 - Update to NetHack 3.6.3 * Tue Aug 13 2019 Ron Olson - 3.6.2-3 - Removed Group tag and clean section * Thu Jul 25 2019 Fedora Release Engineering - 3.6.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Mon May 13 2019 Ron Olson - 3.6.2-1 - Update to NetHack3.6.2 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-79b80b66d9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The nethack package is vulnerable to a buffer overflow exploited via a long '-s' command line option. This vulnerability could be used by an attacker to gain gid 'games' on a system where nethack is installed.. -------------------------------------------------------------------------- Debian Security Advisory DSA 316-1
Overflowing a buffer in nethack may lead to privelige escalation to games uid.. - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200302-08 - --------------------------------------------------------------------- PACKAGE : nethack SUMMARY : buffer overflow DATE : 2003-02-18 09:10 UTC EXPLOIT : local - --------------------------------------------------------------------- Overflowing a buffer in nethack may lead to privelige escalation to games uid. Read the full advisory at: http://marc.theaimsgroup.com/?l=bugtraq&m=104489201032144&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running app-games/nethack upgrade to nethack-3.4.0-r6 as follows: emerge sync emerge -u nethack emerge clean - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.