PT-2001-1147 · Unknown+2 · Midnight Commander+1
Published
2001-01-09
·
Updated
2022-01-19
·
CVE-2000-1108
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Midnight Commander (mc) versions 4.5.42 and earlier
Description
The issue allows local users to corrupt files by creating a symbolic link to the target file and specifying that link as a TTY argument in Midnight Commander, due to improper verification of output file descriptors as TTYs.
Recommendations
For Midnight Commander (mc) versions 4.5.42 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Midnight Commander