In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue.
{ "source": "CPE_RANGE", "extracted_events": [ { "introduced": "3.6.1" }, { "fixed": "3.6.6" } ], "cpe": "cpe:2.3:a:nethack:nethack:*:*:*:*:*:*:*:*" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5254.json"