CVE-2004-0232: Medium severity midnight commander midnight commander vulnerability
Published May 5, 2004
·Updated
Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
Affected Software
28 affected components
Midnight commander Midnight commander=4.5.40
Midnight commander Midnight commander=4.5.41
Midnight commander Midnight commander=4.5.42
Midnight commander Midnight commander=4.5.43
Midnight commander Midnight commander=4.5.44
Midnight commander Midnight commander=4.5.45
Midnight commander Midnight commander=4.5.46
Midnight commander Midnight commander=4.5.47
Midnight commander Midnight commander=4.5.48
Midnight commander Midnight commander=4.5.49
Midnight commander Midnight commander=4.5.50
Midnight commander Midnight commander=4.5.51
Midnight commander Midnight commander=4.5.52
Midnight commander Midnight commander=4.5.55
Midnight commander Midnight commander=4.6
SGI ProPack=2.3
SGI ProPack=2.4
Gentoo Linux=0.5
Gentoo Linux=0.7
Gentoo Linux=1.1a
Gentoo Linux=1.2
Gentoo Linux=1.4
Gentoo Linux=1.4-rc1
Gentoo Linux=1.4-rc2
Gentoo Linux=1.4-rc3
Slackware Slackware Linux
Slackware Slackware Linux=9.0
Slackware Slackware Linux=9.1
Event History
May 5, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0232?
CVE-2004-0232 is classified as a high severity vulnerability due to its potential to cause denial of service or execute arbitrary code.
2
How do I fix CVE-2004-0232?
To fix CVE-2004-0232, upgrade Midnight Commander to version 4.6.0 or later.
3
What impact does CVE-2004-0232 have?
CVE-2004-0232 can lead to system crashes or unauthorized code execution on affected systems.
4
Which versions of Midnight Commander are affected by CVE-2004-0232?
Midnight Commander versions prior to 4.6.0, specifically 4.5.40 to 4.5.55, are affected by CVE-2004-0232.
5
Is CVE-2004-0232 a remote or local vulnerability?
CVE-2004-0232 is primarily a local vulnerability that requires user interaction to exploit.