Midnight Commander contains multiple format strings that may allow an attacker to execute arbitrary code. No further details have been provided.
Classification
Location:
Local Access Required,
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Solution
Debian has issued an update. Upgrade to version mc_4.5.55-1.2woody5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.