First published: Tue Jan 09 2001(Updated: )
Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Nighthawk Ax2400 | =4.5.40 | |
Netgear Nighthawk Ax2400 | =4.5.41 | |
Netgear Nighthawk Ax2400 | =4.5.42 | |
Netgear Nighthawk Ax2400 | =4.5.43 | |
Netgear Nighthawk Ax2400 | =4.5.44 | |
Netgear Nighthawk Ax2400 | =4.5.45 | |
Netgear Nighthawk Ax2400 | =4.5.46 | |
Netgear Nighthawk Ax2400 | =4.5.47 | |
Netgear Nighthawk Ax2400 | =4.5.48 | |
Netgear Nighthawk Ax2400 | =4.5.49 | |
Netgear Nighthawk Ax2400 | =4.5.50 | |
Netgear Nighthawk Ax2400 | =4.5.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1109 is considered a medium severity vulnerability due to its potential for privilege escalation among local users.
To fix CVE-2000-1109, upgrade to a version of Midnight Commander later than 4.5.51 where the vulnerability is patched.
CVE-2000-1109 allows local users to gain elevated privileges by exploiting malformed directory names.
Midnight Commander versions 4.5.51 and earlier are vulnerable to CVE-2000-1109.
CVE-2000-1109 cannot be exploited remotely as it requires local access to the system.