Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander...
Vulnerability Description
Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2003-1023
Credits & Attribution
No credits recorded in the NVD database.
References
- http://rhn.redhat.com/errata/RHSA-2004-034.html
- http://secunia.com/advisories/10772
- ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
- http://www.redhat.com/archives/fedora-legacy-announce/2004-May/msg00002.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13247
- ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
- http://secunia.com/advisories/10716
- http://marc.info/?l=bugtraq&m=108118433222764&w=2
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-014.0.txt
- http://fedoranews.org/updates/FEDORA-2004-058.shtml
- http://secunia.com/advisories/10645
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:007
- http://secunia.com/advisories/10823
- http://archive.cert.uni-stuttgart.de/bugtraq/2003/09/msg00309.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000833
- http://www.securityfocus.com/bid/8658
- http://www.debian.org/security/2004/dsa-424
- http://rhn.redhat.com/errata/RHSA-2004-035.html
- http://secunia.com/advisories/10685
- http://secunia.com/advisories/11219
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A822
- http://secunia.com/advisories/9833
- http://secunia.com/advisories/11296
- http://secunia.com/advisories/11268
- http://secunia.com/advisories/11262
- http://security.gentoo.org/glsa/glsa-200403-09.xml
More from midnight commander
View All →Affected Vendor
midnight commander
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.