REDHAT-BUG-2460017: Medium severity GNU Nano vulnerability
Format string vulnerability in nano's statusline(). Directory names containing printf specifiers (%s) are stored in errormessage and later passed as format string to statusline() with no args. Causes stack reads and SEGV.
Verified on nano 8.7 with ASAN. BZ#2455127. Reported by Michał Majchrowicz and Marcin Wyczechowski, AFINE Team.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2460017?
The severity of REDHAT-BUG-2460017 is considered critical due to the potential for stack reads and segmentation faults.
How do I fix REDHAT-BUG-2460017?
To fix REDHAT-BUG-2460017, upgrade to the patched version of GNU nano beyond 8.7.
Which versions of GNU Nano are affected by REDHAT-BUG-2460017?
GNU Nano version 8.7 is the only version affected by REDHAT-BUG-2460017.
What type of vulnerability is REDHAT-BUG-2460017?
REDHAT-BUG-2460017 is a format string vulnerability affecting the handling of directory names.
Who reported the REDHAT-BUG-2460017 vulnerability?
REDHAT-BUG-2460017 was reported by Michał Majchrowicz.