fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/18906 | vdb entry |
http://secunia.com/advisories/13863/ | third party advisory patch vendor advisory |
http://securitytracker.com/id?1012903 | vdb entry |
http://www.debian.org/security/2005/dsa-639 | patch vendor advisory |
http://www.redhat.com/support/errata/RHSA-2005-512.html | vendor advisory |