CVE-2003-1023Improper Restriction of Operations within the Bounds of a Memory Buffer in Commander

7 documents6 sources
Severity
7.5HIGHNVD
EPSS
8.3%
top 7.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateMay 3

Description

Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDmidnight_commander/midnight_commander4.5.52, 4.5.55, 4.6+2
debiandebian/mc< mc 1:4.6.0-4.6.1-pre1-1 (bookworm)

🔴Vulnerability Details

2
GHSA
GHSA-5f9c-w9rv-7v96: Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry2022-05-03
OSV
CVE-2003-1023: Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry2004-01-20

📋Vendor Advisories

2
Red Hat
security flaw2004-01-16
Debian
CVE-2003-1023: mc - Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midni...2003

💬Community

1
Bugzilla
CVE-2003-1023 security flaw2018-08-16