Vulnerability Name:

CVE-2003-1023 (CCN-13247)

Assigned:2003-09-19
Published:2003-09-19
Updated:2017-10-11
Summary:Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CALDERA
Type: UNKNOWN
CSSA-2004-014.0

Source: SGI
Type: UNKNOWN
20040201-01-U

Source: SGI
Type: UNKNOWN
20040202-01-U

Source: BUGTRAQ
Type: UNKNOWN
20030919 uninitialized buffer in midnight commander

Source: CCN
Type: BugTraq Mailing List, Fri Sep 19 2003 - 08:47:23 CDT
uninitialized buffer in midnight commander

Source: MITRE
Type: CNA
CVE-2003-1023

Source: CONECTIVA
Type: UNKNOWN
CLA-2004:833

Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2004:833
mc

Source: FEDORA
Type: UNKNOWN
FEDORA-2004-058

Source: BUGTRAQ
Type: UNKNOWN
20040405 [OpenPKG-SA-2004.009] OpenPKG Security Advisory (mc)

Source: CCN
Type: RHSA-2004-034
Updated mc packages resolve buffer overflow vulnerability

Source: REDHAT
Type: UNKNOWN
RHSA-2004:034

Source: CCN
Type: RHSA-2004-035
mc security update

Source: REDHAT
Type: UNKNOWN
RHSA-2004:035

Source: SECUNIA
Type: UNKNOWN
10645

Source: SECUNIA
Type: UNKNOWN
10685

Source: SECUNIA
Type: UNKNOWN
10716

Source: SECUNIA
Type: UNKNOWN
10772

Source: SECUNIA
Type: UNKNOWN
10823

Source: SECUNIA
Type: UNKNOWN
11219

Source: SECUNIA
Type: UNKNOWN
11262

Source: SECUNIA
Type: UNKNOWN
11268

Source: SECUNIA
Type: UNKNOWN
11296

Source: CCN
Type: SA9833
Midnight Commander VFS symlink buffer overflow

Source: SECUNIA
Type: UNKNOWN
9833

Source: GENTOO
Type: Vendor Advisory
GLSA-200403-09

Source: DEBIAN
Type: UNKNOWN
DSA-424

Source: DEBIAN
Type: DSA-424
mc -- buffer overflow

Source: CCN
Type: GLSA-200403-09
Buffer overflow in Midnight Commander

Source: CCN
Type: SCO Security Advisory CSSA-2004-014.0
OpenLinux: mc Updated packages resolve local buffer overflow vulnerability

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2004:007

Source: CCN
Type: OpenPKG-SA-2004.009
mc

Source: FEDORA
Type: UNKNOWN
FLSA:1224

Source: BID
Type: Vendor Advisory
8658

Source: CCN
Type: BID-8658
Midnight Commander Virtual File System Symlink Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
midnight-commander-vfssresolvesymlink-bo(13247)

Source: XF
Type: UNKNOWN
midnight-commander-vfssresolvesymlink-bo(13247)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:822

Vulnerable Configuration:Configuration 1:
  • cpe:/a:midnight_commander:midnight_commander:4.5.52:*:*:*:*:*:*:*
  • OR cpe:/a:midnight_commander:midnight_commander:4.5.55:*:*:*:*:*:*:*
  • OR cpe:/a:midnight_commander:midnight_commander:4.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20031023
    V
    CVE-2003-1023
    2015-11-16
    oval:org.mitre.oval:def:822
    V
    Midnight Commander vfs_s_resolve_symlink BO
    2007-04-25
    oval:org.debian:def:424
    V
    buffer overflow
    2004-01-16
    BACK
    midnight_commander midnight commander 4.5.52
    midnight_commander midnight commander 4.5.55
    midnight_commander midnight commander 4.6