GNU Midnight Commander contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the program fails to validate input of non-descript format strings. No further details have been provided. This flaw may lead to a loss of integrity and/or availability.
Classification
Location:
Local Access Required,
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, linux vendors Debian, Gentoo, Mandrake, Red Hat, Slackware and SuSE have released patches to address this vulnerability.