Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
202

openSUSE: 2025:14898-1 moderate: nethack-3.4.3-6.1 Advisory Security Update

An update that solves one vulnerability can now be installed.. # nethack-3.4.3-6.1 on GA media Announcement ID: openSUSE-SU-2025:14898-1 Rating: moderate Cross-References: * CVE-2020-5253 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the nethack-3.4.3-6.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * nethack 3.4.3-6.1 ## References: * https://www.suse.com/security/cve/CVE-2020-5253.html . Install the latest openSUSE security update for nethack-3.4.3-6.1 to address a moderate vulnerability impacting your system.. update, solves, vulnerability, installed, nethack-3, media, announ. . LinuxSecurity.com Team

Calendar%202 Mar 17, 2025 OpenSUSE
203

Mageia 7: MGASA-2021-0077 Critical: NetHack Buffer Overflow Exploit

Updated nethack packages fix security vulnerabilities: NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to . MGASA-2021-0077 - Updated nethack packages fix security vulnerabilities Publication date: 10 Feb 2021 URL: https://advisories.mageia.org/MGASA-2021-0077.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-19905, CVE-2020-5209, CVE-2020-5210, CVE-2020-5211, CVE-2020-5212, CVE-2020-5213, CVE-2020-5214, CVE-2020-5254 Updated nethack packages fix security vulnerabilities: NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files (CVE-2019-19905). In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options (CVE-2020-5209). In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options (CVE-2020-5210). In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files (CVE-2020-5211). In NetHack before 3.6.5, anextremely long value for the MENUCOLOR configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files (CVE-2020-5212). In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files (CVE-2020-5213). In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files (CVE-2020-5214). In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited (CVE-2020-5254). The nethack package has been updated to version 3.6.6, fixing these issues and other bugs. See the upstream release notes for details. References: - https://bugs.mageia.org/show_bug.cgi?id=26228 - https://nethack.org/v362/release.html - https://nethack.org/v363/release.html - https://nethack.org/v364/release.html - https://nethack.org/v365/release.html - https://nethack.org/v366/release.html - https://www.nethack.org/security/CVE-2019-19905.html - https://www.nethack.org/security/CVE-2020-5209.html - https://www.nethack.org/security/CVE-2020-5210.html - https://www.nethack.org/security/CVE-2020-5211.html - https://www.nethack.org/security/CVE-2020-5212.html - https://www.nethack.org/security/CVE-2020-5213.html - https://www.nethack.org/security/CVE-2020-5214.html - https://www.nethack.org/security/CVE-2020-5254.html - https://www.cve.org/CVERecord?id=CVE-2019-19905 -https://www.cve.org/CVERecord?id=CVE-2020-5209 - https://www.cve.org/CVERecord?id=CVE-2020-5210 - https://www.cve.org/CVERecord?id=CVE-2020-5211 - https://www.cve.org/CVERecord?id=CVE-2020-5212 - https://www.cve.org/CVERecord?id=CVE-2020-5213 - https://www.cve.org/CVERecord?id=CVE-2020-5214 - https://www.cve.org/CVERecord?id=CVE-2020-5254 SRPMS: - 7/core/nethack-3.6.6-1.mga7 . The revamped NetHack component resolves critical memory corruption vulnerabilities in Mageia, significantly boosting system defenses.. NetHack Update, Mageia Security, Buffer Overflow Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 10, 2021 Critical Mageia
89

Fedora: 2019-79b80b66d9 Critical: Nethack 3.6.4 Privilege Escalation Fix

Update to NetHack 3.6.4 - fixes security issue with privilege escalation: http://nethack.org/security/index.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-79b80b66d9 2020-01-03 20:35:14.417550 --------------------------------------------------------------------------------Name : nethack Product : Fedora 30 Version : 3.6.4 Release : 1.fc30 URL : https://nethack.org Summary : A rogue-like single player dungeon exploration game Description : NetHack is a single player dungeon exploration game that runs on a wide variety of computer systems, with a variety of graphical and text interfaces all using the same game engine. Unlike many other Dungeons & Dragons-inspired games, the emphasis in NetHack is on discovering the detail of the dungeon and not simply killing everything in sight - in fact, killing everything in sight is a good way to die quickly. Each game presents a different landscape - the random number generator provides an essentially unlimited number of variations of the dungeon and its denizens to be discovered by the player in one of a number of characters: you can pick your race, your role, and your gender. --------------------------------------------------------------------------------Update Information: Update to NetHack 3.6.4 - fixes security issue with privilege escalation: http://nethack.org/security/index.html --------------------------------------------------------------------------------ChangeLog: * Thu Dec 19 2019 Ron Olson - 3.6.4-1 - Update to NetHack 3.6.4 * Mon Dec 9 2019 Ron Olson - 3.6.3-1 - Update to NetHack 3.6.3 * Tue Aug 13 2019 Ron Olson - 3.6.2-3 - Removed Group tag and clean section * Thu Jul 25 2019 Fedora Release Engineering - 3.6.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Mon May 13 2019 Ron Olson - 3.6.2-1 - Update to NetHack3.6.2 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-79b80b66d9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . A critical update for NetHack 3.6.4 on Fedora fixes significant privilege escalation issues.. update, nethack, fixes, security, privilege, escalation, //nethack, org/securit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 03, 2020 Critical Fedora
87

Debian: DSA 316-1 Critical: Nethack Buffer Overflow Exploit

The nethack package is vulnerable to a buffer overflow exploited via a long '-s' command line option. This vulnerability could be used by an attacker to gain gid 'games' on a system where nethack is installed.. -------------------------------------------------------------------------- Debian Security Advisory DSA 316-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Matt Zimmerman June 11th, 2003 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : nethack Vulnerability : buffer overflow, incorrect permissions Problem-Type : local Debian-specific: no CVE Id : CAN-2003-0358 CAN-2003-0359 The nethack package is vulnerable to a buffer overflow exploited via a long '-s' command line option. This vulnerability could be used by an attacker to gain gid 'games' on a system where nethack is installed. Additionally, some setgid binaries in the nethack package have incorrect permissions, which could allow a user who gains gid 'games' to replace these binaries, potentially causing other users to execute malicious code when they run nethack. For the stable distribution (woody) these problems have been fixed in version 3.4.0-3.0woody3. For the old stable distribution (potato) problem xxx has been fixed in version 3.3.0-7potato1. For the unstable distribution (sid) these problems are fixed in version 3.4.1-1. We recommend that you update your nethack package. Upgrade Instructions -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages Debian GNU/Linux 2.2 alias potato --------------------------------- Source archives: Size/MD5 checksum: 6556457b20023bb6993cf7b67eb3d6a1f92 Size/MD5 checksum: 18692 13ac890591e25dab8ceed16f72e1f471 Size/MD5 checksum: 2887417 cf9f4039408321f39c3ef733455cb73a Alpha architecture: Size/MD5 checksum: 1398066 713fcbb55b30327e41e27d6bcb6d607b ARM architecture: Size/MD5 checksum: 1117428 73c2db664578473ef6659cab5cc4d6ef Intel IA-32 architecture: Size/MD5 checksum: 1022056 db40676e291e8df8a4e361bcbfffe7bf Motorola 680x0 architecture: Size/MD5 checksum: 978610 2b11d697920115da6d6221ff0a561c28 PowerPC architecture: Size/MD5 checksum: 1128166 97049fd8d1f264630e8388646f5b35e0 Sun Sparc architecture: Size/MD5 checksum: 1148254 a4ca25a566409ce3ff5bb84dc68b7b15 Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 748 3b19c11e859addf7387327edc9919dda Size/MD5 checksum: 67431 178cb16dc35eba59d3f2cb8d9bcc82c9 Size/MD5 checksum: 3270905 0093f14fbbe449d5b188bfb6aa4eae4f Architecture independent components: Size/MD5 checksum: 12996 adc0f1e825fbaf6d051ebe9ce6d113fd Alpha architecture: Size/MD5 checksum: 448546 e22a529c9f6dd56f754e65c143e888bf Size/MD5 checksum: 1159370 7cb61bf9e18ab76ea49e8f5d07789b86 Size/MD5 checksum: 1166088 9a04f218f4f12986991f231f32d78657 Size/MD5 checksum: 1099536 4ade2cb58891fbf4612861e621de668a ARM architecture: Size/MD5 checksum: 430974 73bb44aa965b99c8dc95dab7789aba7b Size/MD5 checksum: 891296 68a140761542ca2047adfd77ccee72c9 Size/MD5 checksum: 908178 b5c7b5764ff27dffa7228848cacbf7c6 Size/MD5 checksum: 826270 9090d14c531d1d6cd5ec555742aa39dc Intel IA-32 architecture: Size/MD5 checksum: 427996 cbd2cccef376e1986d3d30489ef41f46 Size/MD5 checksum: 790660 6fc1683852e67991d7b8326313d3dada Size/MD5 checksum: 812066 bd0720e9b7ff4394388557628a782552 Size/MD5 checksum: 722422 3e25c8e6abe0da37c38b18819ba41231 HP Precision architecture: Size/MD5 checksum: 437252 4814c05bfe6becaa61d765c5e16d960b Size/MD5 checksum: 1028208 f3786ca02d6e4a2addc838713c72b541 Size/MD5 checksum: 1050072 a7e2a4df3d68b695a8f115a07d02745c Size/MD5 checksum: 964926 c52414ef50a612a375c50f62f32a9910 Motorola 680x0 architecture: Size/MD5 checksum: 425090 d6f27579b87dc04bbdf3027e03d31c21 Size/MD5 checksum: 744130 6c9d59e42180972c686e9588c34a0dc3 Size/MD5 checksum: 759848 25f8e9bf0bfc3bb214cf44aa53551bb7 Size/MD5 checksum: 677096 1a8fee87a24e387b4cccc82047f56154 Big endian MIPS architecture: Size/MD5 checksum: 437234 285bc9f5ecf31dc795b36d6d3938c198 Size/MD5 checksum: 913234 8307a4a58da664337ffea071f9cfedb3 Size/MD5 checksum: 962694 1f2157ea26bb522e53acadc8474c4b3b Size/MD5 checksum: 884232 d10f2486bdd53389c34be664fbbebf62 Little endian MIPS architecture: Size/MD5 checksum: 436524 df00a3c0227ddeeb6784b40098be977e Size/MD5 checksum: 915438 1d4751a80d3a3b7c1856d3c11e3c42be Size/MD5 checksum: 960486 6eca0d12e7dcb0c2b048074897ce0633 Size/MD5 checksum: 885692 ab561bd3c0d59511cd64bb562504d32a PowerPC architecture: Size/MD5 checksum: 433282 44392c68c6c4642d13a8477e43888edc Size/MD5 checksum: 894054 8caa102c4fc9eaebe14b07573c64e8d6 Size/MD5 checksum: 895404 a23e819c3810747f7133e7716a4c67f1 Size/MD5 checksum: 829348 9ac4bfbec280ba184f53ea25a985423d IBM S/390 architecture: Size/MD5 checksum: 431388 184539e76b551bf4fc906f1b79a582cf Size/MD5 checksum: 872456 9e731f496af24534688fae59e7f24045 Size/MD5 checksum: 876436 7de38b1345a4a25a875ee8126a4f4200 Size/MD5checksum: 807628 d2388393e737ac21317a3e559566ec0d Sun Sparc architecture: Size/MD5 checksum: 440772 ef35b8dc5cc1abbb0276d724656f68c8 Size/MD5 checksum: 911986 0b2eee94e97f64b49f2cd3ff072dc2fa Size/MD5 checksum: 912976 b690faf77cd6a932200779ca36763c95 Size/MD5 checksum: 847972 3668f6f14f7924b1446fad9591bd1abb You may use an automated update by adding the resources from the footer to the proper configuration. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian: Critical nethack Buffer Overflow announces vulnerabilities and necessary updates for affected installations.. nethack, buffer overflow, security advisory, debian, exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 11, 2003 Critical Debian
91

Gentoo: 230401-16 Important: Severe Nethack Memory Leak Vulnerability

Overflowing a buffer in nethack may lead to privelige escalation to games uid.. - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200302-08 - --------------------------------------------------------------------- PACKAGE : nethack SUMMARY : buffer overflow DATE : 2003-02-18 09:10 UTC EXPLOIT : local - --------------------------------------------------------------------- Overflowing a buffer in nethack may lead to privelige escalation to games uid. Read the full advisory at: http://marc.theaimsgroup.com/?l=bugtraq&m=104489201032144&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running app-games/nethack upgrade to nethack-3.4.0-r6 as follows: emerge sync emerge -u nethack emerge clean - --------------------------------------------------------------------- This email address is being protected from spambots. You need JavaScript enabled to view it. - GnuPG key is available at - --------------------------------------------------------------------- . A significant flaw in Nethack could permit unauthorized users to exploit game UID on Gentoo deployments. Prompt updates are highly advised.. Gentoo Nethack Exploit Privilege Escalation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 18, 2003 Important Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200