Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2003-1023

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2003-1023
Last Modified 10 Sep 2008 03:21:29
Published 20 Jan 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2003-1023

Summary

Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.

Vulnerable Systems

Application

  • Midnight Commander 4.5.52

  • Midnight Commander 4.5.55

  • Midnight Commander 4.6


References

BUGTRAQ - 20040405 [OpenPKG-SA-2004.009] OpenPKG Security Advisory (mc)

XF - midnight-commander-vfssresolvesymlink-bo(13247)

BID - 8658

DEBIAN - DSA-424

GENTOO - GLSA-200403-09

REDHAT - RHSA-2004:035

REDHAT - RHSA-2004:034

SGI - 20040201-01-U

FEDORA - FLSA:1224

MANDRAKE - MDKSA-2004:007

SECUNIA - 9833

SECUNIA - 11296

SECUNIA - 11268

SECUNIA - 11262

SECUNIA - 11219

SECUNIA - 10823

SECUNIA - 10772

SECUNIA - 10716

SECUNIA - 10685

SECUNIA - 10645

FEDORA - FEDORA-2004-058

CONECTIVA - CLA-2004:833

BUGTRAQ - 20030919 uninitialized buffer in midnight commander

SGI - 20040202-01-U

CALDERA - CSSA-2004-014.0


Last Updated: 27 May 2016 10:38:08