PT-2001-2522 · Unknown+2 · Midnight Commander+1
Publicado
2001-11-12
·
Atualizado
2022-01-19
·
CVE-2001-1429
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Midnight Commander version 4.5.1
Description
A buffer overflow issue in the mcedit component of Midnight Commander allows local users to cause a denial of service, potentially leading to a segmentation fault, and may also enable the execution of arbitrary code. This can be achieved by using a specially crafted text file.
Recommendations
For Midnight Commander version 4.5.1, consider avoiding the use of mcedit with untrusted text files until a patch is available. As a temporary workaround, restrict the use of mcedit to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Midnight Commander