CVE-2021-36370
Summary
| CVE | CVE-2021-36370 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-30 19:15:00 UTC |
| Updated | 2021-09-08 13:41:00 UTC |
| Description | An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Midnight Commander |
MISC |
midnight-commander.org |
|
| mc/connection.c at master · MidnightCommander/mc · GitHub |
MISC |
github.com |
|
| mc/connection.c at 5c1d3c55dd15356ec7d079084d904b7b0fd58d3e · MidnightCommander/mc · GitHub |
MISC |
github.com |
|
| SSH-MITM Docs - CVE-2021-36370 |
MISC |
docs.ssh-mitm.at |
|
| Midnight Commander 4.8.27 released |
MISC |
mail.gnome.org |
|
| Midnight Commander for Windows - Browse Files at SourceForge.net |
MISC |
sourceforge.net |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182965 Debian Security Update for mc (CVE-2021-36370)
- 355599 Amazon Linux Security Advisory for mc : ALAS2-2023-2147
- 900329 CBL-Mariner Linux Security Update for mc 4.8.21
- 901732 Common Base Linux Mariner (CBL-Mariner) Security Update for mc (6678-1)
- 902944 Common Base Linux Mariner (CBL-Mariner) Security Update for mc (5442)