PT-2005-1069 · Gmc+5 · Gmc+4

Publicado

2005-01-22

·

Atualizado

2022-01-19

·

CVE-2004-1175

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions midnight commander versions 4.5.51 mc versions 4.5.51 mcserv versions 4.5.51 gmc versions 4.5.51
Description The issue allows remote attackers to execute arbitrary programs, potentially using shell metacharacters, due to insecure filename quoting in fish.c. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely.
Recommendations For midnight commander version 4.5.51, consider disabling the vulnerable fish.c component until a patch is available. For mc version 4.5.51, restrict access to the vulnerable module to minimize the risk of exploitation. For mcserv version 4.5.51, avoid using potentially insecure filename quoting in the affected API endpoints until the issue is resolved. For gmc version 4.5.51, as a temporary workaround, consider restricting the use of the vulnerable package to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2022-1068
ALT-PU-2022-1089
BDU:2015-06202
BDU:2015-06415
BDU:2015-06416
CVE-2004-1175
DSA-639-1

Produtos afetados

Alt Linux
Midnight Commander
Gmc
Mc
Mcserv