5.1
CVSSv2

CVE-2012-4463

Published: 10/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote malicious users to execute arbitrary commands via a crafted file name.

Vulnerable Product Search on Vulmon Subscribe to Product

midnight-commander midnight commander 4.8.5

Vendor Advisories

Debian Bug report logs - #689571 CVE-2012-4463: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files Package: mc; Maintainer for mc is Dmitry Smirnov <onlyjob@debianorg>; Source for mc is src:mc (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 4 Oct 201 ...