First published: Sat Jan 22 2005(Updated: )
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Midnight Commander | =4.5.48 | |
GNU Midnight Commander | =4.5.40 | |
GNU Midnight Commander | =4.5.43 | |
GNU Midnight Commander | =4.5.50 | |
GNU Midnight Commander | =4.5.49 | |
GNU Midnight Commander | =4.5.52 | |
GNU Midnight Commander | =4.5.42 | |
GNU Midnight Commander | =4.5.45 | |
GNU Midnight Commander | =4.5.55 | |
GNU Midnight Commander | =4.5.44 | |
GNU Midnight Commander | =4.5.41 | |
GNU Midnight Commander | =4.5.46 | |
GNU Midnight Commander | =4.5.47 | |
GNU Midnight Commander | =4.5.51 | |
GNU Midnight Commander | =4.5.54 | |
GNU Midnight Commander | =4.6 | |
Red Hat Enterprise Linux | =2.1 | |
SUSE Linux | =9.2 | |
Debian GNU/Linux | =3.0 | |
SUSE Linux | =9.0 | |
Red Hat Linux Advanced Workstation | =2.1 | |
Debian GNU/Linux | =3.0 | |
SUSE Linux | =8.2 | |
Debian GNU/Linux | =3.0 | |
Debian GNU/Linux | =3.0 | |
Red Hat Enterprise Linux | =2.1 | |
Turbolinux Server | =7.0 | |
SUSE Linux | =9.0 | |
Debian GNU/Linux | =3.0 | |
SUSE Linux | =8.0 | |
Debian GNU/Linux | =3.0 | |
Debian GNU/Linux | =3.0 | |
Turbolinux Workstation | =7.0 | |
Debian GNU/Linux | =3.0 | |
Red Hat Linux Advanced Workstation | =2.1 | |
SUSE Linux | =8.0 | |
SUSE Linux | =9.1 | |
Turbolinux Workstation | =8.0 | |
Debian GNU/Linux | =3.0 | |
Red Hat Enterprise Linux | =2.1 | |
Debian GNU/Linux | =3.0 | |
Red Hat Enterprise Linux | =2.1 | |
Turbolinux Server | =8.0 | |
Gentoo Linux | ||
Debian GNU/Linux | =3.0 | |
Debian GNU/Linux | =3.0 | |
SUSE Linux | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1175 has a severity rating that allows for remote execution of arbitrary code due to insecure filename quoting.
To fix CVE-2004-1175, update Midnight Commander to a version that has addressed this vulnerability.
CVE-2004-1175 affects Midnight Commander versions 4.5.40 through 4.5.55.
Yes, CVE-2004-1175 can be exploited remotely, allowing attackers to execute arbitrary programs.
CVE-2004-1175 is classified as a remote code execution vulnerability due to insecure filename handling.