CVE-2021-36370
30.08.2021, 19:15
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.Enginsight
| Vendor | Product | Version |
|---|---|---|
| midnight-commander | midnight_commander | 𝑥 ≤ 4.8.26 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mc |
|
Common Weakness Enumeration
References