Sorry to add this so late, but upgrading the book to mc-4.6.1 will fix the
following vulnerabilities present in 4.6.0:
CAN-2004-0226, CAN-2004-0231, CAN-2004-0232, CAN-2003-1023
of these, CAN-2003-1023 is a remote attack during symlink conversion,
CAN-2004-0226 is multiple buffer overflows leading to DoS
and appears to fix the following (that is, a gentoo patch to fix these is all
either already applied or doesn't apply because they've been fixed in other ways):
CAN-2004-1004, CAN-2004-1005, CAN-2004-1092, CAN-2004-1076 (the usual overflows,
underflows, format string, and DoS by freeing unallocated memory).
Milestone 6.1 deleted