CVE-2020-5253
9.8
CRITICAL
CVSS 3.1
EPSS 0.21%
Description
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.
How to fix CVE-2020-5253
To remediate CVE-2020-5253, upgrade the affected package to a fixed version below.
- Debian/nethack—upgrade to 3.6.0-1 or later
Is CVE-2020-5253 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.6.0-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |