CVE-2012-4463
Publication date 10 October 2012
Last updated 24 July 2024
Ubuntu priority
Description
Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mc | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
|