CVE-2004-1175

8 documents7 sources
Severity
7.5HIGH
EPSS
0.9%
top 23.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateApr 29

Description

fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

Debianmc< 1:4.6.0-4.6.1-pre3-1+3
NVDsuse/suse_linux6 versions+5

Also affects: Debian Linux 3.0, Enterprise Linux 2.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7hfv-2p5w-ww28: fish2022-04-29
OSV
CVE-2004-1175: fish2005-04-14
CVEList
CVE-2004-1175: fish2005-01-22

📋Vendor Advisories

2
Red Hat
security flaw2005-01-14
Debian
CVE-2004-1175: mc - fish.c in midnight commander allows remote attackers to execute arbitrary progra...2004

💬Community

2
Bugzilla
CVE-2004-1175 security flaw2018-08-16
Bugzilla
CAN-2004-1009 Multiple mc issues (CAN-2004-1090 CAN-2004-1091 CAN-2004-1093 CAN-2004-1174 CAN-2004-1175 CAN-2005-0763)2005-05-24