7.5
CVSSv2

CVE-2004-1175

Published: 14/04/2005 Updated: 19/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

fish.c in midnight commander allows remote malicious users to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

midnight commander midnight commander 4.5.40

midnight commander midnight commander 4.5.41

midnight commander midnight commander 4.5.48

midnight commander midnight commander 4.5.49

midnight commander midnight commander 4.5.44

midnight commander midnight commander 4.5.45

midnight commander midnight commander 4.5.52

midnight commander midnight commander 4.5.54

midnight commander midnight commander 4.5.42

midnight commander midnight commander 4.5.43

midnight commander midnight commander 4.5.50

midnight commander midnight commander 4.5.51

midnight commander midnight commander 4.5.46

midnight commander midnight commander 4.5.47

midnight commander midnight commander 4.5.55

midnight commander midnight commander 4.6

debian debian linux 3.0

redhat enterprise linux 2.1

redhat linux advanced workstation 2.1

suse suse linux 9.0

suse suse linux 9.1

gentoo linux

suse suse linux 8.0

suse suse linux 8.1

turbolinux turbolinux server 8.0

turbolinux turbolinux workstation 7.0

turbolinux turbolinux workstation 8.0

suse suse linux 9.2

turbolinux turbolinux server 7.0

suse suse linux 8.2

Vendor Advisories

Synopsis mc security update Type/Severity Security Advisory: Moderate Topic Updated mc packages that fix several security issues are now available forRed Hat Enterprise Linux 21This update has been rated as having moderate security impact by the Red HatSecurity Response Team Description ...
Andrew V Samoilov has noticed that several bugfixes which were applied to the source by upstream developers of mc, the midnight commander, a file browser and manager, were not backported to the current version of mc that Debian ships in their stable release The Common Vulnerabilities and Exposures Project identifies the following vulnerabilities: ...