VulnerabilityModified
CVE-2003-0358
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.
MEDIUM 4.6EPSS 1.22%
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- falconseye project/falconseye · nethack/nethack · debian/debian linux
- Source
- cve@mitre.org
References
- http://nethack.sourceforge.net/v340/bugmore/secpatch.txtPatch, Third Party Advisory
- http://www.debian.org/security/2003/dsa-316Third Party Advisory
- http://www.debian.org/security/2003/dsa-350Third Party Advisory
- http://www.securityfocus.com/archive/1/311172/2003-02-08/2003-02-14/0Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/6806Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11283Third Party Advisory, VDB Entry
- http://nethack.sourceforge.net/v340/bugmore/secpatch.txtPatch, Third Party Advisory
- http://www.debian.org/security/2003/dsa-316Third Party Advisory
- http://www.debian.org/security/2003/dsa-350Third Party Advisory
- http://www.securityfocus.com/archive/1/311172/2003-02-08/2003-02-14/0Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/6806Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11283Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.