CVE-2019-19905: Nethack
Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.
NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.
Affected products
- Nethack Nethack: from 3.6.0, before 3.6.4 (fixed in 3.6.4)
Published 2019-12-19. Last modified 2026-06-17.