Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
89

Fedora Core 4: 2006-137 Moderate: mc Software Update Overview

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-137 2006-03-07 ---------------------------------------------------------------------Product : Fedora Core 4 Name : mc Version : 4.6.1a Release : 5.fc4 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. ---------------------------------------------------------------------* Tue Mar 7 2006 Jindrich Novy 4.6.1a-5.fc4 - fix hotkey conflict in Layout options (#183282) - move syntax configuration file from /usr/share/mc to /etc/mc - save layout settings pernamently for showing free space, not only for current session (#182127) - fix audio bindings, make firefox default html binding - mc no more segfaults when edited file contains x80 (#181611) - make mc FHS compliant: store config files in /etc/mc and extfs/*.ini files in /etc/mc/extfs instead of /usr/share/mc (#2188) ---------------------------------------------------------------------This update can be downloaded from: b01137ecdb9944719daf8e61c12a04d724b29d14 SRPMS/mc-4.6.1a-5.fc4.src.rpm 7f1c1b31f494fa4723d41eff52ebe677a004b07f ppc/mc-4.6.1a-5.fc4.ppc.rpm a4951748950df6e88125f292d514e9de1a831a1f ppc/debug/mc-debuginfo-4.6.1a-5.fc4.ppc.rpm 21b7cb79288ab85ec8829faadc67a3aeef07e5b3 x86_64/mc-4.6.1a-5.fc4.x86_64.rpm 4d1183838044bb0454a57b2d06699e5cf7591b03 x86_64/debug/mc-debuginfo-4.6.1a-5.fc4.x86_64.rpm 14fa047a542db87117c6bf2451aa198632c470a3 i386/mc-4.6.1a-5.fc4.i386.rpm 5abdd04beafe91cf21f9373d8ad3605186c8cff7 i386/debug/mc-debuginfo-4.6.1a-5.fc4.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important update alert for Fedora Core 4 delivering crucial enhancements to the Midnight Commander application mc.. Fedora Core 4, Midnight Commander, Software Maintenance, Update Management. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2006 Fedora
89

Fedora Core 4: 2005-424 Moderate: mc File Handling Improvement

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-424 2005-06-20 ---------------------------------------------------------------------Product : Fedora Core 4 Name : mc Version : 4.6.1a Release : 0.10.FC4 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support if you are running GPM. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. ---------------------------------------------------------------------* Thu Jun 16 2005 Jindrich Novy 4.6.1a-0.10.FC4 - update to more recent mc version to fix problems with dislaying sizes of files larger than 2GB (#160295) - drop spaceprompt patch - applied in newer version - add mcview ---------------------------------------------------------------------This update can be downloaded from: 7bbcc1a93336bb795ac4503587cb0ed4 SRPMS/mc-4.6.1a-0.10.FC4.src.rpm 87265f7ecb1c3b127411132f10289537 ppc/mc-4.6.1a-0.10.FC4.ppc.rpm e99ea4a8679e705d0ee83c0ee27020f4 ppc/debug/mc-debuginfo-4.6.1a-0.10.FC4.ppc.rpm 5ecc82c8346a1872c781ceac72ba4fb6 x86_64/mc-4.6.1a-0.10.FC4.x86_64.rpm 07f9af8e21cf9d2dcb1aeb040bb8efe4 x86_64/debug/mc-debuginfo-4.6.1a-0.10.FC4.x86_64.rpm 8c27bf8a3f677184f09c6e5125c13189 i386/mc-4.6.1a-0.10.FC4.i386.rpm df1b09160d631dea715405e8014bcf63 i386/debug/mc-debuginfo-4.6.1a-0.10.FC4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Midnight Commander release for Fedora Core 4 improves file management with important corrections for extensive files.Get the update today!. Midnight Commander, Fedora Update, File Manager, Software Patch. . LinuxSecurity.com Team

Calendar%202 Jun 20, 2005 Fedora
98

Red Hat: RHSA-2005:512-01 Moderate: mc Denial of Service Fix

Updated mc packages that fix several security issues are now available for Red Hat Enterprise Linux 2.1. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: mc security update Advisory ID: RHSA-2005:512-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:512.html Issue date: 2005-06-16 Updated on: 2005-06-16 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2005-0763 - ---------------------------------------------------------------------1. Summary: Updated mc packages that fix several security issues are now available for Red Hat Enterprise Linux 2.1. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: Midnight Commander is a visual shell much like a file manager. Several denial of service bugs were found in Midnight Commander. These bugs could cause Midnight Commander to hang or crash if a victim opens a carefully crafted file. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-1009, CAN-2004-1090, CAN-2004-1091, CAN-2004-1093 and CAN-2004-1174 to these issues. A filename quoting bug was found in Midnight Commander's FISH protocol handler. If a victim connects via embedded SSH support to a host containing a carefully crafted filename, arbitrary code may be executed as the user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1175 to this issue. Abuffer overflow bug was found in the way Midnight Commander handles directory completion. If a victim uses completion on a maliciously crafted directory path, it is possible for arbitrary code to be executed as the user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0763 to this issue. Users of mc are advised to upgrade to these packages, which contain backported security patches to correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 158671 - CAN-2004-1009 Multiple mc issues (CAN-2004-1090 CAN-2004-1091 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2005-0763) 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 9e805a0d7578118dd90b7afc8f8ea38f mc-4.5.51-36.8.src.rpm i386: e2ce1ca37f0725b120fa91d68579e381 gmc-4.5.51-36.8.i386.rpm bdc096816859dace0dde57ab3fffcb53 mc-4.5.51-36.8.i386.rpm ba21d0bddad88febd13325e551403e2e mcserv-4.5.51-36.8.i386.rpm ia64: 43a53ce5a7ec823b9531437ec7f51a79 gmc-4.5.51-36.8.ia64.rpm 59287fee62f48ce8c8fb72f923c923d7 mc-4.5.51-36.8.ia64.rpm be6ee2ff486ab9e9c14fefb620532175 mcserv-4.5.51-36.8.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 9e805a0d7578118dd90b7afc8f8ea38f mc-4.5.51-36.8.src.rpm ia64: 43a53ce5a7ec823b9531437ec7f51a79 gmc-4.5.51-36.8.ia64.rpm 59287fee62f48ce8c8fb72f923c923d7 mc-4.5.51-36.8.ia64.rpm be6ee2ff486ab9e9c14fefb620532175 mcserv-4.5.51-36.8.ia64.rpm Red HatEnterprise Linux WS version 2.1: SRPMS: 9e805a0d7578118dd90b7afc8f8ea38f mc-4.5.51-36.8.src.rpm i386: e2ce1ca37f0725b120fa91d68579e381 gmc-4.5.51-36.8.i386.rpm bdc096816859dace0dde57ab3fffcb53 mc-4.5.51-36.8.i386.rpm ba21d0bddad88febd13325e551403e2e mcserv-4.5.51-36.8.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CAN-2004-1009 https://www.cve.org/CVERecord?id=CAN-2004-1090 https://www.cve.org/CVERecord?id=CAN-2004-1091 https://www.cve.org/CVERecord?id=CAN-2004-1093 https://www.cve.org/CVERecord?id=CAN-2004-1174 https://www.cve.org/CVERecord?id=CAN-2004-1175 https://www.cve.org/CVERecord?id=CAN-2005-0763 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2005 Red Hat, Inc. . SUSE has released a comprehensive security patch addressing various vulnerabilities in OpenSUSE Leap 15.3 packages.. Red Hat Advisory, mc Security, Enterprise Linux Update. . LinuxSecurity.com Team

Calendar%202 Jun 16, 2005 Red Hat
89

Fedora Core: 2005-334 Moderate: mc Memory Allocation Fix

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-334 2005-04-22 ---------------------------------------------------------------------Product : Fedora Core 3 Name : mc Version : 4.6.1 Release : 0.14.FC3 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support if you are running GPM. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. ---------------------------------------------------------------------* Thu Apr 21 2005 Jindrich Novy 4.6.1-0.14.FC3 - fix invalid memory allocation in menu.c (#155468) * Wed Apr 20 2005 Jindrich Novy 4.6.1-0.13.FC3 - fix refusal to chdir/start file action when spaces are typed in command prompt and Enter is pressed (#151637) - add displaying of username and hostname in xterm title - fix truncation to lower 32bits in statfs (src/mountlist.c) - fix hang when copying/moving some weird named files (#155412) - fix broken charset conversion feature in the .utf8 patch, memory leak and warning fixes, the patch is from Andrew V. Samoilov (#154516) ---------------------------------------------------------------------This update can be downloaded from: 7e2cba8060d52954938cd1f88072e2c2 SRPMS/mc-4.6.1-0.14.FC3.src.rpm e227f7f29cf4fc67331dd368ba8179eb x86_64/mc-4.6.1-0.14.FC3.x86_64.rpm 94e424d526848b4f75fa1b33773a5392 x86_64/debug/mc-debuginfo-4.6.1-0.14.FC3.x86_64.rpm d85bce76a186fdffc69877678a897722 i386/mc-4.6.1-0.14.FC3.i386.rpm 598abde0e9035a7c7dccd9eb321e114f i386/debug/mc-debuginfo-4.6.1-0.14.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date'command. -----------------------------------------------------------------------fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Fedora Update for mc version 4.6.1 addresses multiple concerns, including improvements to memory management and enhanced file manipulation capabilities.. Fedora Core, mc File Manager, Memory Fix, Update Notification. . LinuxSecurity.com Team

Calendar%202 Apr 22, 2005 Fedora
87

Debian 3.0: DSA 698-1 Moderate Security Update for mc Buffer Overflow

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 698-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze March 29th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : mc Vulnerability : buffer overflow Problem-Type : local Debian-specific: no CVE ID : CAN-2005-0763 An unfixed buffer overflow has been discovered by Andrew V. Samoilov in mc, the midnight commander, a file browser and manager. This update also fixes a regression from DSA 497. For the stable distribution (woody) this problem has been fixed in version 4.5.55-1.2woody6. For the unstable distribution (sid) this problem has already been fixed. We recommend that you upgrade your mc packages. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 798 8e99dd740d8ffae2c41a90a6b116f229 Size/MD5 checksum: 52176 73bc0707bc6bda5e3ba6066985dc774e Size/MD5 checksum: 4850321 82772e729bb2ecfe486a6c219ebab09f Alpha architecture: Size/MD5 checksum: 1186538 9239cbf4199a6544b3ca6332fd52db6f Size/MD5 checksum: 562996 72dbc715e7a7283e11e29fea64552f30 Size/MD5 checksum: 1351898 63a8e1afcbba209db727d92d4955a8c9 ARM architecture: Size/MD5 checksum: 10284088826cb0c5a44b5af496dfeba6d607d55 Size/MD5 checksum: 480688 f6a09cce37d13577e92b373b75cc574c Size/MD5 checksum: 1352032 5dfd20bcf483f407c6731773070c87c3 Intel IA-32 architecture: Size/MD5 checksum: 994490 459f7317ab45b42d003116efacfa196e Size/MD5 checksum: 455232 aab393d3264175b8575cfaf66220f753 Size/MD5 checksum: 1351810 e1471d6e5f49bcd92e12ca9a73b74c33 Intel IA-64 architecture: Size/MD5 checksum: 1435522 a3a000b0de5e6fa4cafaaf58263e47f7 Size/MD5 checksum: 689234 441e904cc527473e05b47b78d5c4bd2f Size/MD5 checksum: 1351796 3e61ead9025a69305e554d63d7abf636 HP Precision architecture: Size/MD5 checksum: 1144534 4c2c57ec173ceed338bc9e44c882f670 Size/MD5 checksum: 541246 2dbf858ac3c53d54baccca0ca3d04031 Size/MD5 checksum: 1352288 cea79758caf2b6f33f989614d924c965 Motorola 680x0 architecture: Size/MD5 checksum: 957858 d7028898ea3a35f85f78a7f087e694b2 Size/MD5 checksum: 437062 cd05897db0003c22f7bb18aecd1eec27 Size/MD5 checksum: 1352326 367211fbc6fa342d715416b958ec07b1 Big endian MIPS architecture: Size/MD5 checksum: 1087190 3216349530cf0a9b2b73902084fea281 Size/MD5 checksum: 536944 281b9d6b996d040e2664355571bd0c7a Size/MD5 checksum: 1352256 1ca47ba59015ff24fc0d324db184de31 Little endian MIPS architecture: Size/MD5 checksum: 1081322 02bdddc905c6d80ebcc17b746a5f47b7 Size/MD5 checksum: 535794 c59f3a0071d2c751a1f5f320fd03c932 Size/MD5 checksum: 1352084 5ad918e829a9a31725de8dd687d7a742 PowerPC architecture: Size/MD5 checksum: 1043086 6d6cb89274647fb8eb0a8f8d089dd7bd Size/MD5 checksum: 490208 716ce6d995b02f20452afaf96185fa59 Size/MD5 checksum: 1352208 3fe36051681012611989f15301b13e1a IBM S/390 architecture: Size/MD5 checksum: 1030020 7d9b20ece50fd41ee2de10cb79826bc3 Size/MD5 checksum: 479574 5be9988d0c5fb89e1061fa06d5256327 Size/MD5 checksum: 1352116 bdcdd74197972f260d0aced37f324751 Sun Sparc architecture: Size/MD5 checksum: 1029098 aadd9cfef3188c17de809a51c2c11037 Size/MD5 checksum: 483630 176d603f21a2cc5253facafc5d86dcb2 Size/MD5 checksum: 1352214 5dfcd273857ed952157083c4d33fbcba These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . - --------------------------------------------------------------------------Debian Security Advisory. updated, package, --------------------------------------------------------------------------debian. . LinuxSecurity.com Team

Calendar%202 Mar 29, 2005 Debian
98

Red Hat Enterprise Linux 2.1 RHSA-2005:217-01 Moderate: mc Buffer Overflow

Updated mc packages that fix multiple security issues are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: mc security update Advisory ID: RHSA-2005:217-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:217.html Issue date: 2005-03-04 Updated on: 2005-03-04 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-1004 CAN-2004-1005 CAN-2004-1176 - ---------------------------------------------------------------------1. Summary: Updated mc packages that fix multiple security issues are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: Midnight Commander (mc) is a visual shell, much like a file manager. Several format string bugs were found in Midnight Commander. If a user is tricked by an attacker into opening a specially crafted path with mc, it may be possible to execute arbitrary code as the user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1004 to this issue. Several buffer overflow bugs were found in Midnight Commander. If a user is tricked by an attacker into opening a specially crafted file or path with mc, it may be possible to execute arbitrary code as the user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1005 to this issue. A buffer underflow bug was found in Midnight Commander. If a malicious local user is able to modify the extfs.ini file, it could bepossible to execute arbitrary code as a user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1176 to this issue. Users of mc should upgrade to these updated packages, which contain a backported patch, and are not vulnerable to this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 148864 - CAN-2004-1004 multiple issues with mc (CAN-2004-1005 CAN-2005-1176) 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 0280014f6cce24b5a7e86224d1a4c20e mc-4.5.51-36.6.src.rpm i386: f9cf57bc299aff9a913dfd4801bf962d gmc-4.5.51-36.6.i386.rpm 34fab95940f7bd986db806c30abf2264 mc-4.5.51-36.6.i386.rpm dd976aa43c29b97804a1149cc64c56e4 mcserv-4.5.51-36.6.i386.rpm ia64: 6f6c8b333239ba869ea8f32e05d9cf04 gmc-4.5.51-36.6.ia64.rpm 012c0f617c2dd9593f53fa8c25839489 mc-4.5.51-36.6.ia64.rpm f067178eaa407dc355cd1e5b5d536b44 mcserv-4.5.51-36.6.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 0280014f6cce24b5a7e86224d1a4c20e mc-4.5.51-36.6.src.rpm ia64: 6f6c8b333239ba869ea8f32e05d9cf04 gmc-4.5.51-36.6.ia64.rpm 012c0f617c2dd9593f53fa8c25839489 mc-4.5.51-36.6.ia64.rpm f067178eaa407dc355cd1e5b5d536b44 mcserv-4.5.51-36.6.ia64.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 0280014f6cce24b5a7e86224d1a4c20e mc-4.5.51-36.6.src.rpm i386: f9cf57bc299aff9a913dfd4801bf962d gmc-4.5.51-36.6.i386.rpm 34fab95940f7bd986db806c30abf2264 mc-4.5.51-36.6.i386.rpm dd976aa43c29b97804a1149cc64c56e4 mcserv-4.5.51-36.6.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-CAN-2004-1004 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1005 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1176 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . Enhanced mc packages address various vulnerabilities; classified as moderate severity by the Red Hat Security Team.. Red Hat Enterprise Linux, mc, security patch. . LinuxSecurity.com Team

Calendar%202 Mar 04, 2005 Red Hat
87

Debian Woody DSA 639-1 Critical: MC Multiple Remote Issues

ndrew V. Samoilov has noticed that several bugfixes which were applied to the source by upstream developers of mc, the midnight commander, a file browser and manager, were not backported to the current version of mc that Debian ships in their stable release.. - --------------------------------------------------------------------------Debian Security Advisory DSA 639-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze January 14th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : mc Vulnerability : several Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-1004 CAN-2004-1005 CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1092 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2004-1176 Andrew V. Samoilov has noticed that several bugfixes which were applied to the source by upstream developers of mc, the midnight commander, a file browser and manager, were not backported to the current version of mc that Debian ships in their stable release. The Common Vulnerabilities and Exposures Project identifies the following vulnerabilities: CAN-2004-1004 Multiple format string vulnerabilities CAN-2004-1005 Multiple buffer overflows CAN-2004-1009 One infinite loop vulnerability CAN-2004-1090 Denial of service via corrupted section header CAN-2004-1091 Denial of service via null dereference CAN-2004-1092 Freeing unallocated memory CAN-2004-1093 Denial of service via use of already freed memory CAN-2004-1174 Denial of service via manipulating non-existing file handles CAN-2004-1175 Unintended program execution via insecure filename quoting CAN-2004-1176 Denial of service via a buffer underflow For the stable distribution (woody) these problems have been fixed in version 4.5.55-1.2woody5 Forthe unstable distribution (sid) these problems should already be fixed since they were backported from current versions. We recommend that you upgrade your mc package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 798 09408d39e539898d3384293454b806a8 Size/MD5 checksum: 51884 64d27d64149013cbbfcbe0d568f872af Size/MD5 checksum: 4850321 82772e729bb2ecfe486a6c219ebab09f Alpha architecture: Size/MD5 checksum: 1186490 28bce9bd85c73413c4e610a83f6c80dd Size/MD5 checksum: 562942 519466cca7aa730a64c5ff629fe64112 Size/MD5 checksum: 1351654 7b7e2ee396427d08f38bb2610533fb25 ARM architecture: Size/MD5 checksum: 1028206 7bc8143ab26f4c42ef99de8f86d30604 Size/MD5 checksum: 480562 94e93aaa4a2dccb4b3acde553091fce7 Size/MD5 checksum: 1351824 cd5a6b905f11fd1661a16e790bf1f588 Intel IA-32 architecture: Size/MD5 checksum: 994986 0c53de4cf192308977e39bb4a7216314 Size/MD5 checksum: 455878 7a09ac156183bc9cee032d674e21587c Size/MD5 checksum: 1351766 fe4f6d051f36930a1533ac7239d5759f Intel IA-64 architecture: Size/MD5 checksum: 1435394 06eb2692e366aa35d3aa39f2903253a7 Size/MD5 checksum: 689186 df58ef7f32905a5c4ade98dab6013ef0 Size/MD5 checksum: 1351652 6530011245a834c8df64a972855b3995 HP Precision architecture: Size/MD5 checksum: 1144490 2d28d59dacd0d57ade92139783897a52 Size/MD5 checksum: 541214 cae4c0accc681cb6d74bebcd38424657 Size/MD5 checksum: 1352116 9b18a11f41ad50f53787129cbb70ee45 Motorola 680x0 architecture: Size/MD5 checksum: 957852 622795322c8d3ccb1f844ca4e80fbc07 Size/MD5 checksum: 436992 28fe37f13b19930168d06a6092e4295e Size/MD5 checksum: 1352176 83bdc91613abb383a2ba65e39b86ec17 Big endian MIPS architecture: Size/MD5 checksum: 1087044 ca4c17d34d697187723ed33915949171 Size/MD5 checksum: 536772 f797b059e1baf558a147296545ab308c Size/MD5 checksum: 1352072 de11cf9737a1835a78db10a9f9e01677 Little endian MIPS architecture: Size/MD5 checksum: 1081206 15555616a4587281d589d6c4d75fff4d Size/MD5 checksum: 535634 44ba98ca679814dca5414955ade5477c Size/MD5 checksum: 1351830 d4dd86b51fd4f80034323d8fb7fed93e PowerPC architecture: Size/MD5 checksum: 1043048 fa3c76890db2a3eb8910630dda4e2ee1 Size/MD5 checksum: 490084 f9a035d0cabd0b5a2208a83ccdb262d3 Size/MD5 checksum: 1352100 07c82e678f74390eb7be89ca324faaad IBM S/390 architecture: Size/MD5 checksum: 1029952 d114807d61819ad87a705d9c145e4e69 Size/MD5 checksum: 479508 b9ce19425fb67653ca449f13a564c5b6 Size/MD5 checksum: 1352022 66290d632d0aeefd2758a9b09c41bd00 Sun Sparc architecture: Size/MD5 checksum: 1029094 189ad1f55bee5b1f45f8286830c59413 Size/MD5 checksum: 483478 f693c3a851ff549e7ea1e64dc993f776 Size/MD5 checksum: 1352114 e26e3f182414e28488950d059bfeee61 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . ---------------------------------------------------------------------------Debian Security Advisory. ndrew, samoilov, noticed, bugfixes, which, applied, source, upstream. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 14, 2005 Critical Debian
89

Fedora Core 2: 2004-273 Moderate: mc extfs vfs Vulnerability

Security fix for extfs vfs vulnerability in mc.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-273 2004-09-01 --------------------------------------------------------------------- Product : Fedora Core 2 Name : mc Version : 4.6.0 Release : 17.fc2 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support if you are running GPM. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. --------------------------------------------------------------------- Update Information: Security fix for https://bugzilla.redhat.com/show_bug.cgi?id=127973. CAN-2004-0494 extfs vfs vulnerability in mc --------------------------------------------------------------------- * Sat Aug 21 2004 Jakub Jelinek 4.6.0-17.fc2 - 3 more quoting omissions in a.in * Sat Aug 21 2004 Jakub Jelinek 4.6.0-17 - fix shell quoting in extfs perl scripts (Leonard den Ottolander, #127973, CAN-2004-0494) * Tue Jun 15 2004 Elliot Lee - rebuilt --------------------------------------------------------------------- This update can be downloaded from: aadb93bb8a2b047c79a4c5be7da28edb SRPMS/mc-4.6.0-17.fc2.src.rpm 2907d996d845c03dd9ff5cc0bcf1ec84 x86_64/mc-4.6.0-17.fc2.x86_64.rpm 10fa4d7b2d7e7abc48015d23004c903b x86_64/debug/mc-debuginfo-4.6.0-17.fc2.x86_64.rpm 5da38fc92a6d8f57148d57eab6f6f251 i386/mc-4.6.0-17.fc2.i386.rpm 11104e0480ab66addf52e4f30b9e9870 i386/debug/mc-debuginfo-4.6.0-17.fc2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Update to address extfs vfs vulnerability in Midnight Commander forFedora Core 2, boosting comprehensive security measures.. Fedora Core 2, extfs issue, Midnight Commander, security patch, software management. . LinuxSecurity.com Team

Calendar%202 Sep 01, 2004 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200