ALT-PU-2014-1024-1
Closed vulnerabilities
Published: 2012-10-10
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2012-4463
Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.
Severity: MEDIUM (5.1)
References:
- [oss-security] 20121003 CVE Request (minor) -- mc: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files
- [oss-security] 20121003 CVE Request (minor) -- mc: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files
- [oss-security] 20121003 Re: CVE Request (minor) -- mc: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files
- [oss-security] 20121003 Re: CVE Request (minor) -- mc: Improper sanitization of MC_EXT_SELECTED variable when viewing multiple files
- 55777
- 55777
- https://bugs.gentoo.org/show_bug.cgi?id=436518#c7
- https://bugs.gentoo.org/show_bug.cgi?id=436518#c7
- https://bugzilla.redhat.com/show_bug.cgi?id=862813
- https://bugzilla.redhat.com/show_bug.cgi?id=862813
- midnight-commander-code-exec(79033)
- midnight-commander-code-exec(79033)
- https://www.midnight-commander.org/ticket/2913
- https://www.midnight-commander.org/ticket/2913
Closed bugs
[FR] rpm extfs: REQUIRES += versions
Кодировка utf8 должна быть явно указана в /usr/share/man/ru/man1/mc.1.bz2