Vulnerability Name: | CVE-2003-1023 (CCN-13247) | ||||||||||||||||
Assigned: | 2003-09-19 | ||||||||||||||||
Published: | 2003-09-19 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CALDERA Type: UNKNOWN CSSA-2004-014.0 Source: SGI Type: UNKNOWN 20040201-01-U Source: SGI Type: UNKNOWN 20040202-01-U Source: BUGTRAQ Type: UNKNOWN 20030919 uninitialized buffer in midnight commander Source: CCN Type: BugTraq Mailing List, Fri Sep 19 2003 - 08:47:23 CDT uninitialized buffer in midnight commander Source: MITRE Type: CNA CVE-2003-1023 Source: CONECTIVA Type: UNKNOWN CLA-2004:833 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2004:833 mc Source: FEDORA Type: UNKNOWN FEDORA-2004-058 Source: BUGTRAQ Type: UNKNOWN 20040405 [OpenPKG-SA-2004.009] OpenPKG Security Advisory (mc) Source: CCN Type: RHSA-2004-034 Updated mc packages resolve buffer overflow vulnerability Source: REDHAT Type: UNKNOWN RHSA-2004:034 Source: CCN Type: RHSA-2004-035 mc security update Source: REDHAT Type: UNKNOWN RHSA-2004:035 Source: SECUNIA Type: UNKNOWN 10645 Source: SECUNIA Type: UNKNOWN 10685 Source: SECUNIA Type: UNKNOWN 10716 Source: SECUNIA Type: UNKNOWN 10772 Source: SECUNIA Type: UNKNOWN 10823 Source: SECUNIA Type: UNKNOWN 11219 Source: SECUNIA Type: UNKNOWN 11262 Source: SECUNIA Type: UNKNOWN 11268 Source: SECUNIA Type: UNKNOWN 11296 Source: CCN Type: SA9833 Midnight Commander VFS symlink buffer overflow Source: SECUNIA Type: UNKNOWN 9833 Source: GENTOO Type: Vendor Advisory GLSA-200403-09 Source: DEBIAN Type: UNKNOWN DSA-424 Source: DEBIAN Type: DSA-424 mc -- buffer overflow Source: CCN Type: GLSA-200403-09 Buffer overflow in Midnight Commander Source: CCN Type: SCO Security Advisory CSSA-2004-014.0 OpenLinux: mc Updated packages resolve local buffer overflow vulnerability Source: MANDRAKE Type: UNKNOWN MDKSA-2004:007 Source: CCN Type: OpenPKG-SA-2004.009 mc Source: FEDORA Type: UNKNOWN FLSA:1224 Source: BID Type: Vendor Advisory 8658 Source: CCN Type: BID-8658 Midnight Commander Virtual File System Symlink Buffer Overflow Vulnerability Source: XF Type: UNKNOWN midnight-commander-vfssresolvesymlink-bo(13247) Source: XF Type: UNKNOWN midnight-commander-vfssresolvesymlink-bo(13247) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:822 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |