CVE-2004-1004

10 documents8 sources
Severity
7.5HIGH
EPSS
0.9%
top 23.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateApr 29

Description

Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

Debianmc< 1:4.6.0-4.6.1-pre3-1+3
NVDsuse/suse_linux6 versions+5

Also affects: Debian Linux 3.0, Enterprise Linux 2.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p79j-c39w-jjj4: Multiple format string vulnerabilities in Midnight Commander (mc) 42022-04-29
OSV
CVE-2004-1004: Multiple format string vulnerabilities in Midnight Commander (mc) 42005-04-14
CVEList
CVE-2004-1004: Multiple format string vulnerabilities in Midnight Commander (mc) 42005-01-22

💥Exploits & PoCs

3
Exploit-DB
Berlios GPSD 2.7 - Remote Format String (Metasploit)2007-01-08
Exploit-DB
Berlios GPSD 1.91-1 < 2.7-2 - Format String2005-05-25
Exploit-DB
OpenText FirstClass 8.0 - HTTP Daemon /Search Remote Denial of Service2004-12-15

📋Vendor Advisories

2
Red Hat
security flaw2005-02-14
Debian
CVE-2004-1004: mc - Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and ear...2004

💬Community

1
Bugzilla
CVE-2004-1004 security flaw2018-08-16