4 ms·
https://www.nethack.org/security/CVE-2020-5254.html https://www.nethack.org/security/CVE-2020-5254.html Never considered nethack as part of my security model
by kalium_xyz 7y ago
https://www.nethack.org/security/CVE-2020-5254.html https://www.nethack.org/security/CVE-2020-5254.html
Never considered nethack as part of my security model
- naniwaduni 7y agoEverything with a setuid/setgid should be viewed with suspicion.
- stevekemp 7y agoYears ago I reported a security bug (CVE-2004-0103) in the nethack-like game "crawl". In that case it involved copying the contents of an environmental variable into a fixed size buffer. I've just checked my bug report, where I wrote: Demonstrating this bug is quite challenging as it involves: * Finding pizza. * Eating the pizza and having a two in three chance of your message (getenv( "CRAWL_PIZZA")) being used. Fun memories; I should audit some more code soon.
- vorpalhex 7y agoThere were (and probably still are) some shared *nix systems that allowed you to connect and play/spectate Nethack games.
- htfy96 7y agoI often play with ssh nethack@hardfought.org . Multiple variants available.