Bug 113849 - CAN-2003-1023 mc stack overflow
CAN-2003-1023 mc stack overflow
Status: CLOSED ERRATA
Product: Red Hat Linux
Classification: Retired
Component: mc (Show other bugs)
9
All Linux
medium Severity medium
: ---
: ---
Assigned To: Jakub Jelinek
David Lawrence
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2004-01-19 10:25 EST by Mark J. Cox (Product Security)
Modified: 2007-04-18 13:01 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-01-29 07:46:23 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Mark J. Cox (Product Security) 2004-01-19 10:25:55 EST
A buffer overflow has been found in Midnight Commander's virtual
filesystem code. Specifically, a stack-based buffer overflow in
vfs_s_resolve_symlink of vfs/direntry.c allows remote attackers to
execute arbitrary code during symlink conversion.

Errata RHSA-2004:034 in progress
Comment 1 Leonard den Ottolander 2004-01-29 07:07:36 EST
This is in ERRATA and can be closed as such.

Comment 2 Mark J. Cox (Product Security) 2004-01-29 07:46:23 EST
Yeah, RHSA-2004:034 was released on the 21st:
http://rhn.redhat.com/errata/RHSA-2004-034.html
Comment 3 Leonard den Ottolander 2004-01-30 05:27:08 EST
And what about Fedora Core (bug #114540)? A test update was made
available on the 19th, but no announcement was made on either the test
list, the main list or the devel list.

This update should be announced and moved to the main tree.

While I am at it let me shamelessly plug the one line fix from bug
#112644. Please get it in testing. I've been using it for over a month
without any problem.

Note You need to log in before you can comment on or make changes to this bug.