CVE-2019-19905

Name
CVE-2019-19905
Description
NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/NetHack/NetHack/commit/f001de79542b8c38b1f8e6d7eaefbbd28ab94b47
Issue Tracking https://bugs.debian.org/947005
Patch https://github.com/NetHack/NetHack/commit/f4a840a48f4bcf11757b3d859e9d53cc9d5ef226
Vendor Advisory https://nethack.org/security/
Third Party Advisory https://github.com/NetHack/NetHack/security/advisories/GHSA-3cm7-rgh5-9pq5

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:nethack:nethack:*:*:*:*:*:*:*:* nethack >= 3.6.0 < 3.6.4

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nethack edge-community 3.6.4-r0 None fixed
nethack 3.22-community 3.6.4-r0 None fixed
nethack 3.21-community 3.6.4-r0 None fixed
nethack 3.20-community 3.6.4-r0 None fixed
nethack 3.19-community 3.6.4-r0 None fixed
nethack 3.18-community 3.6.4-r0 None fixed
nethack 3.17-community 3.6.4-r0 None fixed