PT-2001-1148 · Unknown+2 · Midnight Commander+1
Published
2001-01-09
·
Updated
2022-01-19
·
CVE-2000-1109
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Midnight Commander (mc) versions 4.5.51 and earlier
Description
The issue arises from the improper processing of malformed directory names when a user opens a directory. This allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.
Recommendations
For Midnight Commander (mc) versions 4.5.51 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Midnight Commander