PT-2001-1147 · Unknown+2 · Midnight Commander+1

Published

2001-01-09

·

Updated

2022-01-19

·

CVE-2000-1108

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Midnight Commander (mc) versions 4.5.42 and earlier
Description The issue allows local users to corrupt files by creating a symbolic link to the target file and specifying that link as a TTY argument in Midnight Commander, due to improper verification of output file descriptors as TTYs.
Recommendations For Midnight Commander (mc) versions 4.5.42 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2022-1068
ALT-PU-2022-1089
CVE-2000-1108

Affected Products

Alt Linux
Midnight Commander