LWN.net Logo

Fedora alert FEDORA-2012-19349 (mc)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 17 Update: mc-4.8.6-2.fc17
Date:  Fri, 07 Dec 2012 03:27:01 +0000
Message-ID:  <20121207032701.1B86F209CC@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-19349 2012-11-29 03:26:42 -------------------------------------------------------------------------------- Name : mc Product : Fedora 17 Version : 4.8.6 Release : 2.fc17 URL : http://www.midnight-commander.org/ Summary : User-friendly text console file manager and visual shell Description : Midnight Commander is a visual shell much like a file manager, only with many more features. It is a text mode application, but it also includes mouse support. Midnight Commander's best features are its ability to FTP, view tar and zip files, and to poke into RPMs for specific files. -------------------------------------------------------------------------------- Update Information: sanitize of MC_EXT_SELECTED variable when viewing multiple files, CVE-2012-4463 (#862814) https://www.midnight-commander.org/ticket/2913 -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 28 2012 Jindrich Novy <jnovy@redhat.com> 4.8.6-2 - sanitize of MC_EXT_SELECTED variable when viewing multiple files, CVE-2012-4463 (#862814) https://www.midnight-commander.org/ticket/2913 * Thu Sep 20 2012 Jindrich Novy <jnovy@redhat.com> 4.8.6-1 - update to 4.8.6 (#857512) * Tue Sep 11 2012 Jindrich Novy <jnovy@redhat.com> 4.8.5-1 - update to 4.8.5 (#815307) * Mon Jul 23 2012 Jindrich Novy <jnovy@redhat.com> 4.8.4-2 - BR: libssh2-devel for SFTP support - BR: aspell-devel * Wed Jul 18 2012 Jindrich Novy <jnovy@redhat.com> 4.8.4-1 - update to 4.8.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #862813 - CVE-2012-4463 mc: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files https://bugzilla.redhat.com/show_bug.cgi?id=862813 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mc' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds