<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>157028</bug_id>
          
          <creation_ts>2006-12-03 15:38 0000</creation_ts>
          <short_desc>www-client/links vulnerablitiy in smb:// URL handling (CVE-2006-5925)</short_desc>
          <delta_ts>2007-03-31 18:20:24 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/22905/</bug_file_loc>
          <status_whiteboard>B3? [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>arthur@arthurkoziel.de</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>mips@gentoo.org</cc>
    
    <cc>vanquirius@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>arthur@arthurkoziel.de</who>
            <bug_when>2006-12-03 15:38:05 0000</bug_when>
            <thetext>Hi,
please bump www-client/links to pre26.

In the changelog, there&apos;s also a entry about a severe security bug
http://links.twibright.com/download/ChangeLog

Tue Nov 28 23:13:38 MET 2006 mikulas:

	Fixed severe security bug: &apos;&quot;&apos; and &apos;;&apos; in smb:// url could be used for
	remote command execution.

Thanks!</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vanquirius@gentoo.org</who>
            <bug_when>2006-12-03 17:33:31 0000</bug_when>
            <thetext>Thanks, 2.1_pre26 in cvs.
Security, I believe you take it from here :-).

Cheers</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2006-12-04 00:32:35 0000</bug_when>
            <thetext>x86 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2006-12-04 06:27:01 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2006-12-04 07:38:07 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>grobian@gentoo.org</who>
            <bug_when>2006-12-04 08:54:01 0000</bug_when>
            <thetext>moved to prefix.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ahf@0x90.dk</who>
            <bug_when>2006-12-04 09:16:33 0000</bug_when>
            <thetext>Stable on Alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2006-12-04 10:24:49 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2006-12-04 10:44:38 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-12-05 00:47:49 0000</bug_when>
            <thetext>Correcting component.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>malc@gentoo.org</who>
            <bug_when>2006-12-05 14:20:08 0000</bug_when>
            <thetext>amd64 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-12-07 02:24:42 0000</bug_when>
            <thetext>hard to rate this... B3 might be closes

from Secunia:
Successful exploitation allows exposure of sensitive information or manipulation of data, but requires that the user visits a malicious &quot;smb://&quot; URL or gets redirected to such an URL by a malicious URL, and that the user has the smbclient program installed.

security please vote</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-12-07 03:34:35 0000</bug_when>
            <thetext>I tend to vote NO. How often do you use lins for smb:// stuff?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>frilled@gentoo.org</who>
            <bug_when>2006-12-07 03:42:01 0000</bug_when>
            <thetext>I guess it&apos;s not whether you would use it, but you could be enticed to use it by a malicious site. If this works for &lt;IMG SRC=&quot;smb://...&quot;&gt; tags for example, you&apos;ll be screwed. (Note that I don&apos;t know whether it does, I just remember a bug like that in firefox.) Redirection will not automatically screw you, though (at least not in the default conf).

I tend to vote yes. I admit it&apos;s &quot;thin&quot;, but it&apos;s also bad ^_^
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-12-10 12:51:40 0000</bug_when>
            <thetext>i vote yes... and isn&apos;t it a B2 instead of B3 ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-12-10 13:05:39 0000</bug_when>
            <thetext>ok, agreed... let&apos;s have a GLSA</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2006-12-15 07:56:39 0000</bug_when>
            <thetext>GLSA 200612-16</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-03-31 18:20:24 0000</bug_when>
            <thetext>ia64 done</thetext>
          </long_desc>
      
    </bug>

</bugzilla>