CVE-2019-19905 describes a critical buffer overflow vulnerability in NetHack 3.6.x versions prior to 3.6.4. This flaw occurs when the game processes excessively long lines within configuration files, potentially leading to arbitrary code execution. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with no user interaction required, allowing for complete compromise of confidentiality, integrity, and availability. It poses a significant risk to systems where NetHack is installed with elevated privileges or on shared systems allowing user-uploaded configurations. Currently, there is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion or media coverage, suggesting a low level of public awareness despite its critical severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.6.0, < 3.6.4CPE matchmatch criteria | cpe:2.3:a:nethack:nethack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.