Midnight Commander Multiple Unspecified Vulnerabilities

BID:10242

Info

Midnight Commander Multiple Unspecified Vulnerabilities

Bugtraq ID: 10242
Class: Unknown
CVE: CVE-2004-0226
CVE-2004-0231
CVE-2004-0232
Remote: No
Local: No
Published: Apr 30 2004 12:00AM
Updated: Jul 12 2009 04:06AM
Credit: Disclosure of these issues is credited to Jacub Jelinek.
Vulnerable: Slackware Linux 9.1
Slackware Linux 9.0
Slackware Linux -current
SGI ProPack 2.4
SGI ProPack 2.3
Midnight Commander Midnight Commander 4.6
+ OpenPKG OpenPKG 2.0
+ OpenPKG OpenPKG 1.3
+ OpenPKG OpenPKG Current
+ Redhat Enterprise Linux AS 3
+ Redhat Enterprise Linux AS 2.1 IA64
+ Redhat Enterprise Linux AS 2.1
+ Redhat Enterprise Linux ES 3
+ Redhat Enterprise Linux ES 2.1 IA64
+ Redhat Enterprise Linux ES 2.1
+ Redhat Enterprise Linux WS 3
+ Redhat Enterprise Linux WS 2.1 IA64
+ Redhat Enterprise Linux WS 2.1
+ Redhat Fedora Core1
+ Redhat Linux 9.0 i386
+ S.u.S.E. Linux Personal 9.0
+ S.u.S.E. Linux Personal 8.2
Midnight Commander Midnight Commander 4.5.55
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
+ Mandriva Linux Mandrake 9.0
+ SuSE Linux 8.1
+ SuSE Linux 8.0
Midnight Commander Midnight Commander 4.5.52
Midnight Commander Midnight Commander 4.5.51
+ SCO OpenLinux Server 3.1.1
+ SCO OpenLinux Workstation 3.1.1
Midnight Commander Midnight Commander 4.5.50
Midnight Commander Midnight Commander 4.5.49
Midnight Commander Midnight Commander 4.5.48
Midnight Commander Midnight Commander 4.5.47
Midnight Commander Midnight Commander 4.5.46
Midnight Commander Midnight Commander 4.5.45
Midnight Commander Midnight Commander 4.5.44
Midnight Commander Midnight Commander 4.5.43
Midnight Commander Midnight Commander 4.5.42
Midnight Commander Midnight Commander 4.5.41
Midnight Commander Midnight Commander 4.5.40
Gentoo Linux 1.4 _rc3
Gentoo Linux 1.4 _rc2
Gentoo Linux 1.4 _rc1
Gentoo Linux 1.4
Gentoo Linux 1.2
Gentoo Linux 1.1 a
Gentoo Linux 0.7
Gentoo Linux 0.5
Not Vulnerable:

Discussion

Midnight Commander Multiple Unspecified Vulnerabilities

It has been reported that Midnight Commander is prone to multiple, unspecified vulnerabilities. These issues are due to various design and boundary condition errors.

These issues could be leveraged by an attacker to execute arbitrary code on an affected system, which may facilitate unauthorized access. It is also possible for an attacker to carry out symbolic link attacks against an affected system, potentially facilitating a system wide denial of service.

Exploit / POC

Midnight Commander Multiple Unspecified Vulnerabilities

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Midnight Commander Multiple Unspecified Vulnerabilities

Solution:
Debian has released advisory DSA 497-1 dealing with these issues. Please see the referenced advisory for more information.

Mandrake has released advisory MDKSA-2004:039 along with fixes dealing with these issues. Users are advised to see the referenced advisory for more information and details on obtaining fixes.

Red Hat has released advisory RHSA-2004:173-01 dealing with these issues for their Red Hat Linux 9.0 distribution. Please see the referenced advisory for more information.

Red Hat Fedora has released advisory FEDORA-2004-112 dealing with these issues for their Fedora Linux project. Please see the referenced advisory for more information.

SuSE Linux has released advisory SuSE-SA:2004:012 dealing with this issue. Please see the referenced advisory for more information and details on obtaining fixes.

Slackware Linux has released advisory SSA:2004-136-01 dealing with these issues. Please see the referenced advisory for more information and fixes.

Gentoo Linux has released advisory GLSA 200405-21 dealing with these issues. They have advised that affected users take the following steps: All Midnight Commander users should upgrade to the latest stable version:

# emerge sync

# emerge -pv ">=app-misc/mc-4.6.0-r7
# emerge ">=app-misc/mc-4.6.0-r7"

Please see the referenced Gentoo advisory for more information.

Silicon Graphics has released advisory 20040508-01-U and fixes dealing with this and other issues for SGI ProPack 2.4. Please see the referenced advisory for more information.


Slackware Linux -current

SGI ProPack 2.4

Midnight Commander Midnight Commander 4.5.55

Midnight Commander Midnight Commander 4.6

Slackware Linux 9.0

Slackware Linux 9.1

References

Midnight Commander Multiple Unspecified Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report