Affected versions: 3.6.0, 3.6.1, 3.6.2, 3.6.3
First Patched Version: 3.6.4
A buffer overflow issue exists when reading very long lines from a NetHack configuration file (usually named .nethackrc).
This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files.
All users are urged to upgrade to NetHack 3.6.4 as soon as possible.
Additional information related to this advisory, if any, will be made available at https://nethack.org/security.
18-Dec-2019 NetHack 3.6.4 released with fix.
13-Dec-2019 Bug reported.
Hosted courtesy of alt.org.
NetHack is Copyright 1985-2019 by Stichting Mathematisch Centrum
and M. Stephenson. See
our license for details.
This site is Copyright 1999-2019 by Kenneth Lorber, Kensington, Maryland.