Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
91

Gentoo: GLSA-202310-15 Critical: OpenSSH Protocol Exposure Risk

A remotely-exploitable buffer overflow in Midnight Commander allows arbitrary code to be run on a user's computer. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200403-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Buffer overflow in Midnight Commander Date: March 29, 2004 Bugs: #45957 ID: 200403-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A remotely-exploitable buffer overflow in Midnight Commander allows arbitrary code to be run on a user's computer Background ========= Midnight Commander is a visual file manager. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- app-misc/mc = 4.6.0-r5 Description ========== A stack-based buffer overflow has been found in Midnight Commander's virtual filesystem. Impact ===== This overflow allows an attacker to run arbitrary code on the user's computer during the symlink conversion process. Workaround ========= While a workaround is not currently known for this issue, all users are advised to upgrade to the latest version of the affected package. Resolution ========= All users should upgrade to the current version of the affected package: # emerge sync # emerge -pv "> =app-misc/mc-4.6.0-r5" # emerge "> =app-misc/mc-4.6.0-r5" References ========= [ 1 ] https://www.cve.org/CVERecord?id=CAN-2003-1023 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should beaddressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. . A buffer overflow vulnerability in Midnight Commander can enable remote code execution. It's crucial to update to address this serious security issue.. Gentoo Security, Midnight Commander, Code Execution Risk. . LinuxSecurity.com Team

Calendar%202 Mar 31, 2004 Gentoo
89

Fedora 4.6.0-8.4 Moderate: Mc Buffer Overflow Fix for CAN-2003-1023

update CAN-2003-1023 fix to still make vfs symlinks relative, but with bounds checking. Fedora Update Notification FEDORA-2004-058 2004-02-09 --------------------------------------------------------------------- Name : mc Version : 4.6.0 Release : 8.4 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support if you are running GPM. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. --------------------------------------------------------------------- * Sat Jan 31 2004 Jakub Jelinek 4.6.0-8.4 - fix previous patch * Fri Jan 30 2004 Jakub Jelinek 4.6.0-8.3 - update php.syntax file (#112645) - fix crash with large syntax file (#112644) * Fri Jan 23 2004 Jakub Jelinek 4.6.0-8.2 - update CAN-2003-1023 fix to still make vfs symlinks relative, but with bounds checking * Sat Jan 17 2004 Warren Togami 4.6.0-8.1 - rebuild for FC1 * Sat Jan 17 2004 Warren Togami 4.6.0-7 - BuildRequires glib2-devel, slang-devel, XFree86-devel, e2fsprogs-devel, gettext - Copyright -> License - PreReq -> Requires - Explicit zero epoch in versioned dev dep - /usr/share/mc directory ownership - Improve summary - (Seth Vidal QA) fix for CAN-2003-1023 (Security) --------------------------------------------------------------------- This update can be downloaded from: b4b3bffbc6c96184041b80d04f231264 SRPMS/mc-4.6.0-8.4.src.rpm 40cb4c39b4d1fa21194cbe352f9e8d57 i386/mc-4.6.0-8.4.i386.rpm 9cbeef390a1326737c471dd75de69546 i386/debug/mc-debuginfo-4.6.0-8.4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. fedora-announce-list Info Page . The patch for Fedora's mc buffer overflow resolves CAN-2003-1023 vulnerabilities detected on 2004-02-09.. buffer overflow, midnight commander, fedora update. . LinuxSecurity.com Team

Calendar%202 Feb 18, 2004 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200