4.6
CVSSv2

CVE-2000-1109

Published: 09/01/2001 Updated: 10/10/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Midnight Commander (mc) 4.5.51 and previous versions does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.

Vulnerable Product Search on Vulmon Subscribe to Product

midnight commander midnight commander 4.5.40

midnight commander midnight commander 4.5.41

midnight commander midnight commander 4.5.48

midnight commander midnight commander 4.5.49

midnight commander midnight commander 4.5.42

midnight commander midnight commander 4.5.43

midnight commander midnight commander 4.5.50

midnight commander midnight commander 4.5.51

midnight commander midnight commander 4.5.46

midnight commander midnight commander 4.5.47

midnight commander midnight commander 4.5.44

midnight commander midnight commander 4.5.45

Vendor Advisories

It has been reported that a local user could tweak Midnight Commander of another user into executing an arbitrary program under the user id of the person running Midnight Commander This behaviour has been fixed by Andrew V Samoilov We recommend you upgrade your mc package ...