CVE-2020-5253

Source
https://cve.org/CVERecord?id=CVE-2020-5253
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-5253.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-5253
Downstream
Related
Published
2020-03-10T17:15:12.973Z
Modified
2026-03-13T00:42:50.298545Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.

References

Affected packages

Git / github.com/nethack/nethack

Affected ranges

Type
GIT
Repo
https://github.com/nethack/nethack
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.6.0"
        }
    ]
}

Affected versions

Other
MOVE2GIT
NetHack-3.*
NetHack-3.6.0_RC01
NetHack-3.6.0_RC02
NetHack-3.6.0_RC03
NetHack-3.6.0_RC04

Database specific

vanir_signatures
[
    {
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2020-5253-2acee0cf",
        "source": "https://github.com/nethack/nethack/commit/585e9f1b35fda7b47f8d27d12f7e93e12a69a7bc",
        "target": {
            "file": "win/win32/winhack.c"
        },
        "digest": {
            "line_hashes": [
                "312269647539887670774664032978877969594",
                "203008790340323208233340850392220376819",
                "235844713220841089302372100555199115686",
                "164687583317955788998839275239003419194"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2020-5253-788f2728",
        "source": "https://github.com/nethack/nethack/commit/585e9f1b35fda7b47f8d27d12f7e93e12a69a7bc",
        "target": {
            "file": "win/win32/winhack.c",
            "function": "WinMain"
        },
        "digest": {
            "length": 3716.0,
            "function_hash": "4858587609181367127297299164415663259"
        },
        "signature_type": "Function"
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-5253.json"