CVE Vulnerabilities

CVE-2004-1175

Published: Apr 14, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED
root.io minimus.io echohq.com

fish.c in midnight commander allows remote attackers to execute arbitrary programs via insecure filename quoting, possibly using shell metacharacters.

Affected Software

Name Vendor Start Version End Version
Midnight_commander Midnight_commander 4.5.40 (including) 4.5.40 (including)
Midnight_commander Midnight_commander 4.5.41 (including) 4.5.41 (including)
Midnight_commander Midnight_commander 4.5.42 (including) 4.5.42 (including)
Midnight_commander Midnight_commander 4.5.43 (including) 4.5.43 (including)
Midnight_commander Midnight_commander 4.5.44 (including) 4.5.44 (including)
Midnight_commander Midnight_commander 4.5.45 (including) 4.5.45 (including)
Midnight_commander Midnight_commander 4.5.46 (including) 4.5.46 (including)
Midnight_commander Midnight_commander 4.5.47 (including) 4.5.47 (including)
Midnight_commander Midnight_commander 4.5.48 (including) 4.5.48 (including)
Midnight_commander Midnight_commander 4.5.49 (including) 4.5.49 (including)
Midnight_commander Midnight_commander 4.5.50 (including) 4.5.50 (including)
Midnight_commander Midnight_commander 4.5.51 (including) 4.5.51 (including)
Midnight_commander Midnight_commander 4.5.52 (including) 4.5.52 (including)
Midnight_commander Midnight_commander 4.5.54 (including) 4.5.54 (including)
Midnight_commander Midnight_commander 4.5.55 (including) 4.5.55 (including)
Midnight_commander Midnight_commander 4.6 (including) 4.6 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Enterprise Linux WS version 2.1 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *
Mc Ubuntu dapper *
Mc Ubuntu devel *
Mc Ubuntu edgy *
Mc Ubuntu feisty *

References