Back

HIGH

m4: code execution via -F argument

Published Apr 9, 2008

Description

Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option. NOTE: it is not clear when this issue crosses privilege boundaries.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this to be a security issue. After careful analysis of this issue the Red Hat Product Security has determined that this bug has no security impact outside of expected m4 behavior.

Metrics

Weaknesses (0)

No CWE recorded.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 9, 2008
Updated Aug 7, 2024
Reserved Apr 6, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Apr 2, 2008