Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-24809

Опубликовано: 17 фев. 2023
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal input to the "C" (call) command can cause a buffer overflow and crash the NetHack process. This vulnerability may be a security issue for systems that have NetHack installed suid/sgid and for shared systems. For all systems, it may result in a process crash. This issue is resolved in NetHack 3.6.7. There are no known workarounds.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nethack:nethack:*:*:*:*:*:*:*:*
Версия от 3.6.2 (включая) до 3.6.7 (исключая)

EPSS

Процентиль: 18%
0.00056
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-120
CWE-120

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal input to the "C" (call) command can cause a buffer overflow and crash the NetHack process. This vulnerability may be a security issue for systems that have NetHack installed suid/sgid and for shared systems. For all systems, it may result in a process crash. This issue is resolved in NetHack 3.6.7. There are no known workarounds.

CVSS3: 5.5
debian
почти 3 года назад

NetHack is a single player dungeon exploration game. Starting with ver ...

EPSS

Процентиль: 18%
0.00056
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-120
CWE-120