NULL Pointer Dereference in Midnight Commander Could Lead to X Operation Silently Failing
CVE-2023-45925

Currently unrated

Key Information:

Vendor
GNU
Vendor
CVE Published:
27 March 2024

Summary

The vulnerability identified in GNU Midnight Commander highlights a NULL pointer dereference occurring within the x_error_handler() function located in tty/x11conn.c. This issue may lead to silent failures in X operations, impacting the usability of the application without providing any indication of errors. Although this vulnerability is contested as a usability concern rather than a security vulnerability, it still poses questions regarding the robustness and user experience associated with this popular terminal file manager.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.