CVE-2004-1175

midnight_commander - Remote Code Execution via Insecure Filename Quoting

Title source: llm
STIX 2.1

Description

fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18906
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13863/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1012903
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-639
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-512.html

Scores

EPSS 0.0095
EPSS Percentile 76.6%

Details

Status published
Products (30)
debian/debian_linux 3.0 (12 CPE variants)
gentoo/linux
midnight_commander/midnight_commander 4.5.40
midnight_commander/midnight_commander 4.5.41
midnight_commander/midnight_commander 4.5.42
midnight_commander/midnight_commander 4.5.43
midnight_commander/midnight_commander 4.5.44
midnight_commander/midnight_commander 4.5.45
midnight_commander/midnight_commander 4.5.46
midnight_commander/midnight_commander 4.5.47
... and 20 more
Published Apr 14, 2005
Tracked Since Feb 18, 2026