CVE-2004-1174: Medium severity midnight commander midnight commander vulnerability
Published Jan 22, 2005
·Updated
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
Affected Software
47 affected components
Midnight commander Midnight commander=4.5.48
Midnight commander Midnight commander=4.5.40
Midnight commander Midnight commander=4.5.43
Midnight commander Midnight commander=4.5.50
Midnight commander Midnight commander=4.5.49
Midnight commander Midnight commander=4.5.52
Midnight commander Midnight commander=4.5.42
Midnight commander Midnight commander=4.5.45
Midnight commander Midnight commander=4.5.55
Midnight commander Midnight commander=4.5.44
Midnight commander Midnight commander=4.5.41
Midnight commander Midnight commander=4.5.46
Midnight commander Midnight commander=4.5.47
Midnight commander Midnight commander=4.5.51
Midnight commander Midnight commander=4.5.54
Midnight commander Midnight commander=4.6
redhat Enterprise Linux=2.1
SUSE SuSE Linux=9.2
Debian Debian Linux=3.0
SUSE SuSE Linux=9.0
redhat Linux Advanced Workstation=2.1
Debian Debian Linux=3.0
SUSE SuSE Linux=8.2
Debian Debian Linux=3.0
Debian Debian Linux=3.0
redhat Enterprise Linux=2.1
Turbolinux Turbolinux Server=7.0
SUSE SuSE Linux=9.0
Debian Debian Linux=3.0
SUSE SuSE Linux=8.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Turbolinux Turbolinux Workstation=7.0
Debian Debian Linux=3.0
redhat Linux Advanced Workstation=2.1
SUSE SuSE Linux=8.0
SUSE SuSE Linux=9.1
Turbolinux Turbolinux Workstation=8.0
Debian Debian Linux=3.0
redhat Enterprise Linux=2.1
Debian Debian Linux=3.0
redhat Enterprise Linux=2.1
Turbolinux Turbolinux Server=8.0
Gentoo Linux
Debian Debian Linux=3.0
Debian Debian Linux=3.0
SUSE SuSE Linux=8.1
Remediation
Patch Available
Patch Available
Event History
Jan 22, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1174?
CVE-2004-1174 is categorized as a denial of service vulnerability.
2
How do I fix CVE-2004-1174?
To fix CVE-2004-1174, upgrade Midnight Commander to version 4.6 or later.
3
Which versions of Midnight Commander are affected by CVE-2004-1174?
Versions of Midnight Commander prior to 4.6, including 4.5.55 and earlier, are affected by CVE-2004-1174.
4
What does CVE-2004-1174 affect?
CVE-2004-1174 affects the direntry.c module of Midnight Commander.
5
Can CVE-2004-1174 be exploited remotely?
Yes, CVE-2004-1174 can potentially be exploited remotely to cause a denial of service.