LWN.net Logo

mc: command execution

Package(s):mc CVE #(s):CVE-2012-4463
Created:December 7, 2012 Updated:December 12, 2012
Description: From the CVE entry:

Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.

Alerts:
Fedora FEDORA-2012-19349 2012-12-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds