The vendor explicitly states that these products are not affected by this CVE.
- All currently supported Red Hat products
- Summary
- A flaw was found in nnn, a file manager. This vulnerability, known as Shell Command Injection, allows an attacker to execute arbitrary commands. By creating a specially crafted directory name containing shell syntax on a shared filesystem, removable media, or within an extracted archive, an attacker can exploit this flaw. If a victim navigates into this directory and uses the batch copy or move function, the malicious directory name is embedded into a shell command, leading to the execution of the attacker's payload with the privileges of the nnn process.
- Remediation
- No remediation text is recorded.
