CVE-2023-24809

Name
CVE-2023-24809
Description
NetHack is a single player dungeon exploration game. Starting with version 3.6.2 and prior to version 3.6.7, illegal input to the "C" (call) command can cause a buffer overflow and crash the NetHack process. This vulnerability may be a security issue for systems that have NetHack installed suid/sgid and for shared systems. For all systems, it may result in a process crash. This issue is resolved in NetHack 3.6.7. There are no known workarounds.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/NetHack/NetHack/security/advisories/GHSA-2cqv-5w4v-mgch
MISC https://nethack.org/security/CVE-2023-24809.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:nethack:nethack:*:*:*:*:*:*:*:* nethack >= 3.6.2 < 3.6.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nethack 3.17-community 3.6.6-r1 Drew DeVault <sir@cmpwn.com> possibly vulnerable
nethack 3.18-community 3.6.7-r0 Drew DeVault <sir@cmpwn.com> fixed