Gentoo Archives: gentoo-announce

From: Mikle Kolyada <zlogene@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201402-18 ] GNU Midnight Commander: User-assisted execution of arbitrary code
Date: Thu, 20 Feb 2014 11:11:03
Message-Id: 5305E38D.5080208@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201402-18
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: GNU Midnight Commander: User-assisted execution of arbitrary
9 code
10 Date: February 20, 2014
11 Bugs: #436518
12 ID: 201402-18
13
14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
15
16 Synopsis
17 ========
18
19 GNU Midnight Commander does not properly sanitize environment
20 variables, possibly resulting in execution of arbitrary code or Denial
21 of Service.
22
23 Background
24 ==========
25
26 GNU Midnight Commander is a text based file manager.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 app-misc/mc < 4.8.7 >= 4.8.7
35
36 Description
37 ===========
38
39 GNU Midnight Commander does not properly sanitize environment
40 variables.
41
42 Impact
43 ======
44
45 A remote attacker could entice a user to open a specially crafted
46 archive file using GNU Midnight Commander, possibly resulting in
47 execution of arbitrary code with the privileges of the process or a
48 Denial of Service condition.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All GNU Midnight Commander users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=app-misc/mc-4.8.7"
62
63 References
64 ==========
65
66 [ 1 ] CVE-2012-4463
67 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4463
68
69 Availability
70 ============
71
72 This GLSA and any updates to it are available for viewing at
73 the Gentoo Security Website:
74
75 http://security.gentoo.org/glsa/glsa-201402-18.xml
76
77 Concerns?
78 =========
79
80 Security is a primary focus of Gentoo Linux and ensuring the
81 confidentiality and security of our users' machines is of utmost
82 importance to us. Any security concerns should be addressed to
83 security@g.o or alternatively, you may file a bug at
84 https://bugs.gentoo.org.
85
86 License
87 =======
88
89 Copyright 2014 Gentoo Foundation, Inc; referenced text
90 belongs to its owner(s).
91
92 The contents of this document are licensed under the
93 Creative Commons - Attribution / Share Alike license.
94
95 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature