OESA-2022-1771

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2022-1771
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2022-1771.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2022-1771
Upstream
Published
2022-07-22T11:04:01Z
Modified
2025-09-03T06:17:31.662056Z
Summary
mc security update
Details

GNU Midnight Commander is a visual file manager, licensed under GNU General Public License and therefore qualifies as Free Software. It's a feature rich full-screen text mode application that allows you to copy, move and delete files and whole directory trees, search for files and run commands in the subshell. Internal viewer and editor are included.

Security Fix(es):

An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.(CVE-2021-36370)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / mc

Package

Name
mc
Purl
pkg:rpm/openEuler/mc&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.8.28-1.oe1

Ecosystem specific

{
    "noarch": [
        "mc-help-4.8.28-1.oe1.noarch.rpm",
        "mc-python-4.8.28-1.oe1.noarch.rpm"
    ],
    "x86_64": [
        "mc-4.8.28-1.oe1.x86_64.rpm",
        "mc-debugsource-4.8.28-1.oe1.x86_64.rpm",
        "mc-debuginfo-4.8.28-1.oe1.x86_64.rpm"
    ],
    "src": [
        "mc-4.8.28-1.oe1.src.rpm"
    ],
    "aarch64": [
        "mc-debugsource-4.8.28-1.oe1.aarch64.rpm",
        "mc-debuginfo-4.8.28-1.oe1.aarch64.rpm",
        "mc-4.8.28-1.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / mc

Package

Name
mc
Purl
pkg:rpm/openEuler/mc&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.8.28-1.oe1

Ecosystem specific

{
    "noarch": [
        "mc-help-4.8.28-1.oe1.noarch.rpm",
        "mc-python-4.8.28-1.oe1.noarch.rpm"
    ],
    "x86_64": [
        "mc-4.8.28-1.oe1.x86_64.rpm",
        "mc-debugsource-4.8.28-1.oe1.x86_64.rpm",
        "mc-debuginfo-4.8.28-1.oe1.x86_64.rpm"
    ],
    "src": [
        "mc-4.8.28-1.oe1.src.rpm"
    ],
    "aarch64": [
        "mc-4.8.28-1.oe1.aarch64.rpm",
        "mc-debuginfo-4.8.28-1.oe1.aarch64.rpm",
        "mc-debugsource-4.8.28-1.oe1.aarch64.rpm"
    ]
}

openEuler:22.03-LTS / mc

Package

Name
mc
Purl
pkg:rpm/openEuler/mc&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.8.28-1.oe2203

Ecosystem specific

{
    "noarch": [
        "mc-python-4.8.28-1.oe2203.noarch.rpm",
        "mc-help-4.8.28-1.oe2203.noarch.rpm"
    ],
    "x86_64": [
        "mc-debuginfo-4.8.28-1.oe2203.x86_64.rpm",
        "mc-4.8.28-1.oe2203.x86_64.rpm",
        "mc-debugsource-4.8.28-1.oe2203.x86_64.rpm"
    ],
    "src": [
        "mc-4.8.28-1.oe2203.src.rpm"
    ],
    "aarch64": [
        "mc-debugsource-4.8.28-1.oe2203.aarch64.rpm",
        "mc-debuginfo-4.8.28-1.oe2203.aarch64.rpm",
        "mc-4.8.28-1.oe2203.aarch64.rpm"
    ]
}