PT-2001-2522 · Unknown+2 · Midnight Commander+1

Published

2001-11-12

·

Updated

2022-01-19

·

CVE-2001-1429

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Midnight Commander version 4.5.1
Description A buffer overflow issue in the mcedit component of Midnight Commander allows local users to cause a denial of service, potentially leading to a segmentation fault, and may also enable the execution of arbitrary code. This can be achieved by using a specially crafted text file.
Recommendations For Midnight Commander version 4.5.1, consider avoiding the use of mcedit with untrusted text files until a patch is available. As a temporary workaround, restrict the use of mcedit to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2022-1068
ALT-PU-2022-1089
CVE-2001-1429

Affected Products

Alt Linux
Midnight Commander