CVE-2012-4463: Midnight-Commander Midnight Commander
Medium severity, CVSS 5.1. EPSS: 1.9% chance of exploitation in the next 30 days.
Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.
Affected products
- Midnight-Commander Midnight Commander: version 4.8.5 only
Published 2012-10-10. Last modified 2026-06-16.