Guard against buffer overflows when reading in score entries, in case `record' has become corrupted or been maliciously modified. This addresses the part of "#Q101: Security bug in nethack 3.4.3" that we have control over. A Gentoo bug tracking discussion pointed out to us by <email deleted>, describes how that particular Linux distribution makes users be members of the games group, allowing them to modify files in nethack's playground directory when it has been set up in the usual ``setgid games'' manner, thus making score processing in that environment be vulnerable to buffer overrun exploits.
23 KiB
23 KiB