A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.
5.6.1-1build15.9-16.0-16.1-16.2-16.2-1ubuntu0.16.2-1ubuntu0.27.2-17.2-27.2-2build17.2-2ubuntu0.17.2-2ubuntu0.28.4-18.6-18.7-18.7.1-18.7.1-1ubuntu0.12.2.6-1ubuntu12.2.6-1ubuntu1+esm12.4.2-12.4.2-1ubuntu12.4.3-12.5.0-12.5.1-12.5.2-12.5.3-22.5.3-2ubuntu12.5.3-2ubuntu22.5.3-2ubuntu2+esm12.8.6-32.8.7-12.9.0-12.9.1-12.9.2-12.9.3-12.9.3-22.9.3-2ubuntu0.1~esm12.9.3-2ubuntu0.1~esm24.3-14.5-14.7-14.7-24.8-14.8-1ubuntu14.8-1ubuntu1.14.8-1ubuntu1.1+esm1Exploitability
AV:LAC:LPR:LUI:RScope
S:UImpact
C:LI:HA:HCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H