Updated mc packages resolve buffer overflow vulnerability


Thorsten

SSF Facilitymanagement
Staff member
Topic
Updated mc packages that resolve a buffer overflow vulnerability are now
available.
Description
Midnight Commander is a visual shell much like a file manager.

A buffer overflow has been found in Midnight Commander's virtual filesystem
code. Specifically, a stack-based buffer overflow in vfs_s_resolve_symlink
of vfs/direntry.c allows remote attackers to execute arbitrary code during
symlink conversion.

Users of Midnight Commander should install these updated packages, which
resolve this issue.
Affected Channels
Red Hat Linux 9 i386

Fixes
CAN-2003-1023 mc stack overflow

Keywords
buffer, mc, overflow, vfs
CVEs
CAN-2003-1023
References
(none)
Notes
(none)
 
Back
Top