Jacub Jelinek discovered several vulnerabilities in the MidnightCommander, a powerful file manager for GNU/Linux systems.. -------------------------------------------------------------------------- Debian Security Advisory DSA 497-1
A remotely-exploitable buffer overflow in Midnight Commander allows arbitrary code to be run on a user's computer. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200403-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Buffer overflow in Midnight Commander Date: March 29, 2004 Bugs: #45957 ID: 200403-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A remotely-exploitable buffer overflow in Midnight Commander allows arbitrary code to be run on a user's computer Background ========= Midnight Commander is a visual file manager. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- app-misc/mc = 4.6.0-r5 Description ========== A stack-based buffer overflow has been found in Midnight Commander's virtual filesystem. Impact ===== This overflow allows an attacker to run arbitrary code on the user's computer during the symlink conversion process. Workaround ========= While a workaround is not currently known for this issue, all users are advised to upgrade to the latest version of the affected package. Resolution ========= All users should upgrade to the current version of the affected package: # emerge sync # emerge -pv "> =app-misc/mc-4.6.0-r5" # emerge "> =app-misc/mc-4.6.0-r5" References ========= [ 1 ] https://www.cve.org/CVERecord?id=CAN-2003-1023 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should beaddressed to
update CAN-2003-1023 fix to still make vfs symlinks relative, but with bounds checking. Fedora Update Notification FEDORA-2004-058 2004-02-09 --------------------------------------------------------------------- Name : mc Version : 4.6.0 Release : 8.4 Summary : User-friendly text console file manager and visual shell. Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support if you are running GPM. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. --------------------------------------------------------------------- * Sat Jan 31 2004 Jakub Jelinek 4.6.0-8.4 - fix previous patch * Fri Jan 30 2004 Jakub Jelinek 4.6.0-8.3 - update php.syntax file (#112645) - fix crash with large syntax file (#112644) * Fri Jan 23 2004 Jakub Jelinek 4.6.0-8.2 - update CAN-2003-1023 fix to still make vfs symlinks relative, but with bounds checking * Sat Jan 17 2004 Warren Togami 4.6.0-8.1 - rebuild for FC1 * Sat Jan 17 2004 Warren Togami 4.6.0-7 - BuildRequires glib2-devel, slang-devel, XFree86-devel, e2fsprogs-devel, gettext - Copyright -> License - PreReq -> Requires - Explicit zero epoch in versioned dev dep - /usr/share/mc directory ownership - Improve summary - (Seth Vidal QA) fix for CAN-2003-1023 (Security) --------------------------------------------------------------------- This update can be downloaded from: b4b3bffbc6c96184041b80d04f231264 SRPMS/mc-4.6.0-8.4.src.rpm 40cb4c39b4d1fa21194cbe352f9e8d57 i386/mc-4.6.0-8.4.i386.rpm 9cbeef390a1326737c471dd75de69546 i386/debug/mc-debuginfo-4.6.0-8.4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.