Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-137 2006-03-07 ---------------------------------------------------------------------Product : Fedora Core 4 Name : mc Version : 4.6.1a Release : 5.fc4 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. ---------------------------------------------------------------------* Tue Mar 7 2006 Jindrich Novy 4.6.1a-5.fc4 - fix hotkey conflict in Layout options (#183282) - move syntax configuration file from /usr/share/mc to /etc/mc - save layout settings pernamently for showing free space, not only for current session (#182127) - fix audio bindings, make firefox default html binding - mc no more segfaults when edited file contains x80 (#181611) - make mc FHS compliant: store config files in /etc/mc and extfs/*.ini files in /etc/mc/extfs instead of /usr/share/mc (#2188) ---------------------------------------------------------------------This update can be downloaded from: b01137ecdb9944719daf8e61c12a04d724b29d14 SRPMS/mc-4.6.1a-5.fc4.src.rpm 7f1c1b31f494fa4723d41eff52ebe677a004b07f ppc/mc-4.6.1a-5.fc4.ppc.rpm a4951748950df6e88125f292d514e9de1a831a1f ppc/debug/mc-debuginfo-4.6.1a-5.fc4.ppc.rpm 21b7cb79288ab85ec8829faadc67a3aeef07e5b3 x86_64/mc-4.6.1a-5.fc4.x86_64.rpm 4d1183838044bb0454a57b2d06699e5cf7591b03 x86_64/debug/mc-debuginfo-4.6.1a-5.fc4.x86_64.rpm 14fa047a542db87117c6bf2451aa198632c470a3 i386/mc-4.6.1a-5.fc4.i386.rpm 5abdd04beafe91cf21f9373d8ad3605186c8cff7 i386/debug/mc-debuginfo-4.6.1a-5.fc4.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-424 2005-06-20 ---------------------------------------------------------------------Product : Fedora Core 4 Name : mc Version : 4.6.1a Release : 0.10.FC4 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support if you are running GPM. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. ---------------------------------------------------------------------* Thu Jun 16 2005 Jindrich Novy 4.6.1a-0.10.FC4 - update to more recent mc version to fix problems with dislaying sizes of files larger than 2GB (#160295) - drop spaceprompt patch - applied in newer version - add mcview ---------------------------------------------------------------------This update can be downloaded from: 7bbcc1a93336bb795ac4503587cb0ed4 SRPMS/mc-4.6.1a-0.10.FC4.src.rpm 87265f7ecb1c3b127411132f10289537 ppc/mc-4.6.1a-0.10.FC4.ppc.rpm e99ea4a8679e705d0ee83c0ee27020f4 ppc/debug/mc-debuginfo-4.6.1a-0.10.FC4.ppc.rpm 5ecc82c8346a1872c781ceac72ba4fb6 x86_64/mc-4.6.1a-0.10.FC4.x86_64.rpm 07f9af8e21cf9d2dcb1aeb040bb8efe4 x86_64/debug/mc-debuginfo-4.6.1a-0.10.FC4.x86_64.rpm 8c27bf8a3f677184f09c6e5125c13189 i386/mc-4.6.1a-0.10.FC4.i386.rpm df1b09160d631dea715405e8014bcf63 i386/debug/mc-debuginfo-4.6.1a-0.10.FC4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Updated mc packages that fix several security issues are now available for Red Hat Enterprise Linux 2.1. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: mc security update Advisory ID: RHSA-2005:512-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:512.html Issue date: 2005-06-16 Updated on: 2005-06-16 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-1009 CAN-2004-1090 CAN-2004-1091 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2005-0763 - ---------------------------------------------------------------------1. Summary: Updated mc packages that fix several security issues are now available for Red Hat Enterprise Linux 2.1. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: Midnight Commander is a visual shell much like a file manager. Several denial of service bugs were found in Midnight Commander. These bugs could cause Midnight Commander to hang or crash if a victim opens a carefully crafted file. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-1009, CAN-2004-1090, CAN-2004-1091, CAN-2004-1093 and CAN-2004-1174 to these issues. A filename quoting bug was found in Midnight Commander's FISH protocol handler. If a victim connects via embedded SSH support to a host containing a carefully crafted filename, arbitrary code may be executed as the user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1175 to this issue. Abuffer overflow bug was found in the way Midnight Commander handles directory completion. If a victim uses completion on a maliciously crafted directory path, it is possible for arbitrary code to be executed as the user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0763 to this issue. Users of mc are advised to upgrade to these packages, which contain backported security patches to correct these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 158671 - CAN-2004-1009 Multiple mc issues (CAN-2004-1090 CAN-2004-1091 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2005-0763) 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 9e805a0d7578118dd90b7afc8f8ea38f mc-4.5.51-36.8.src.rpm i386: e2ce1ca37f0725b120fa91d68579e381 gmc-4.5.51-36.8.i386.rpm bdc096816859dace0dde57ab3fffcb53 mc-4.5.51-36.8.i386.rpm ba21d0bddad88febd13325e551403e2e mcserv-4.5.51-36.8.i386.rpm ia64: 43a53ce5a7ec823b9531437ec7f51a79 gmc-4.5.51-36.8.ia64.rpm 59287fee62f48ce8c8fb72f923c923d7 mc-4.5.51-36.8.ia64.rpm be6ee2ff486ab9e9c14fefb620532175 mcserv-4.5.51-36.8.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 9e805a0d7578118dd90b7afc8f8ea38f mc-4.5.51-36.8.src.rpm ia64: 43a53ce5a7ec823b9531437ec7f51a79 gmc-4.5.51-36.8.ia64.rpm 59287fee62f48ce8c8fb72f923c923d7 mc-4.5.51-36.8.ia64.rpm be6ee2ff486ab9e9c14fefb620532175 mcserv-4.5.51-36.8.ia64.rpm Red HatEnterprise Linux WS version 2.1: SRPMS: 9e805a0d7578118dd90b7afc8f8ea38f mc-4.5.51-36.8.src.rpm i386: e2ce1ca37f0725b120fa91d68579e381 gmc-4.5.51-36.8.i386.rpm bdc096816859dace0dde57ab3fffcb53 mc-4.5.51-36.8.i386.rpm ba21d0bddad88febd13325e551403e2e mcserv-4.5.51-36.8.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CAN-2004-1009 https://www.cve.org/CVERecord?id=CAN-2004-1090 https://www.cve.org/CVERecord?id=CAN-2004-1091 https://www.cve.org/CVERecord?id=CAN-2004-1093 https://www.cve.org/CVERecord?id=CAN-2004-1174 https://www.cve.org/CVERecord?id=CAN-2004-1175 https://www.cve.org/CVERecord?id=CAN-2005-0763 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2005 Red Hat, Inc. . SUSE has released a comprehensive security patch addressing various vulnerabilities in OpenSUSE Leap 15.3 packages.. Red Hat Advisory, mc Security, Enterprise Linux Update. . LinuxSecurity.com Team
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-334 2005-04-22 ---------------------------------------------------------------------Product : Fedora Core 3 Name : mc Version : 4.6.1 Release : 0.14.FC3 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support if you are running GPM. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. ---------------------------------------------------------------------* Thu Apr 21 2005 Jindrich Novy 4.6.1-0.14.FC3 - fix invalid memory allocation in menu.c (#155468) * Wed Apr 20 2005 Jindrich Novy 4.6.1-0.13.FC3 - fix refusal to chdir/start file action when spaces are typed in command prompt and Enter is pressed (#151637) - add displaying of username and hostname in xterm title - fix truncation to lower 32bits in statfs (src/mountlist.c) - fix hang when copying/moving some weird named files (#155412) - fix broken charset conversion feature in the .utf8 patch, memory leak and warning fixes, the patch is from Andrew V. Samoilov (#154516) ---------------------------------------------------------------------This update can be downloaded from: 7e2cba8060d52954938cd1f88072e2c2 SRPMS/mc-4.6.1-0.14.FC3.src.rpm e227f7f29cf4fc67331dd368ba8179eb x86_64/mc-4.6.1-0.14.FC3.x86_64.rpm 94e424d526848b4f75fa1b33773a5392 x86_64/debug/mc-debuginfo-4.6.1-0.14.FC3.x86_64.rpm d85bce76a186fdffc69877678a897722 i386/mc-4.6.1-0.14.FC3.i386.rpm 598abde0e9035a7c7dccd9eb321e114f i386/debug/mc-debuginfo-4.6.1-0.14.FC3.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date'command. -----------------------------------------------------------------------fedora-announce-list mailing list
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 698-1
Updated mc packages that fix multiple security issues are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: mc security update Advisory ID: RHSA-2005:217-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:217.html Issue date: 2005-03-04 Updated on: 2005-03-04 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-1004 CAN-2004-1005 CAN-2004-1176 - ---------------------------------------------------------------------1. Summary: Updated mc packages that fix multiple security issues are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: Midnight Commander (mc) is a visual shell, much like a file manager. Several format string bugs were found in Midnight Commander. If a user is tricked by an attacker into opening a specially crafted path with mc, it may be possible to execute arbitrary code as the user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1004 to this issue. Several buffer overflow bugs were found in Midnight Commander. If a user is tricked by an attacker into opening a specially crafted file or path with mc, it may be possible to execute arbitrary code as the user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1005 to this issue. A buffer underflow bug was found in Midnight Commander. If a malicious local user is able to modify the extfs.ini file, it could bepossible to execute arbitrary code as a user running Midnight Commander. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1176 to this issue. Users of mc should upgrade to these updated packages, which contain a backported patch, and are not vulnerable to this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 148864 - CAN-2004-1004 multiple issues with mc (CAN-2004-1005 CAN-2005-1176) 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 0280014f6cce24b5a7e86224d1a4c20e mc-4.5.51-36.6.src.rpm i386: f9cf57bc299aff9a913dfd4801bf962d gmc-4.5.51-36.6.i386.rpm 34fab95940f7bd986db806c30abf2264 mc-4.5.51-36.6.i386.rpm dd976aa43c29b97804a1149cc64c56e4 mcserv-4.5.51-36.6.i386.rpm ia64: 6f6c8b333239ba869ea8f32e05d9cf04 gmc-4.5.51-36.6.ia64.rpm 012c0f617c2dd9593f53fa8c25839489 mc-4.5.51-36.6.ia64.rpm f067178eaa407dc355cd1e5b5d536b44 mcserv-4.5.51-36.6.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 0280014f6cce24b5a7e86224d1a4c20e mc-4.5.51-36.6.src.rpm ia64: 6f6c8b333239ba869ea8f32e05d9cf04 gmc-4.5.51-36.6.ia64.rpm 012c0f617c2dd9593f53fa8c25839489 mc-4.5.51-36.6.ia64.rpm f067178eaa407dc355cd1e5b5d536b44 mcserv-4.5.51-36.6.ia64.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 0280014f6cce24b5a7e86224d1a4c20e mc-4.5.51-36.6.src.rpm i386: f9cf57bc299aff9a913dfd4801bf962d gmc-4.5.51-36.6.i386.rpm 34fab95940f7bd986db806c30abf2264 mc-4.5.51-36.6.i386.rpm dd976aa43c29b97804a1149cc64c56e4 mcserv-4.5.51-36.6.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-CAN-2004-1004 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1005 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1176 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . Enhanced mc packages address various vulnerabilities; classified as moderate severity by the Red Hat Security Team.. Red Hat Enterprise Linux, mc, security patch. . LinuxSecurity.com Team
ndrew V. Samoilov has noticed that several bugfixes which were applied to the source by upstream developers of mc, the midnight commander, a file browser and manager, were not backported to the current version of mc that Debian ships in their stable release.. - --------------------------------------------------------------------------Debian Security Advisory DSA 639-1
Security fix for extfs vfs vulnerability in mc.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-273 2004-09-01 --------------------------------------------------------------------- Product : Fedora Core 2 Name : mc Version : 4.6.0 Release : 17.fc2 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support if you are running GPM. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. --------------------------------------------------------------------- Update Information: Security fix for https://bugzilla.redhat.com/show_bug.cgi?id=127973. CAN-2004-0494 extfs vfs vulnerability in mc --------------------------------------------------------------------- * Sat Aug 21 2004 Jakub Jelinek 4.6.0-17.fc2 - 3 more quoting omissions in a.in * Sat Aug 21 2004 Jakub Jelinek 4.6.0-17 - fix shell quoting in extfs perl scripts (Leonard den Ottolander, #127973, CAN-2004-0494) * Tue Jun 15 2004 Elliot Lee - rebuilt --------------------------------------------------------------------- This update can be downloaded from: aadb93bb8a2b047c79a4c5be7da28edb SRPMS/mc-4.6.0-17.fc2.src.rpm 2907d996d845c03dd9ff5cc0bcf1ec84 x86_64/mc-4.6.0-17.fc2.x86_64.rpm 10fa4d7b2d7e7abc48015d23004c903b x86_64/debug/mc-debuginfo-4.6.0-17.fc2.x86_64.rpm 5da38fc92a6d8f57148d57eab6f6f251 i386/mc-4.6.0-17.fc2.i386.rpm 11104e0480ab66addf52e4f30b9e9870 i386/debug/mc-debuginfo-4.6.0-17.fc2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Update to address extfs vfs vulnerability in Midnight Commander forFedora Core 2, boosting comprehensive security measures.. Fedora Core 2, extfs issue, Midnight Commander, security patch, software management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.