Bug 157028 - www-client/links vulnerablitiy in smb:// URL handling (CVE-2006-5925)
|
Bug#:
157028
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: Linux
|
Status: RESOLVED
|
Severity: enhancement
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: arthur@arthurkoziel.de
|
|
Component: Vulnerabilities
|
|
|
URL:
http://secunia.com/advisories/22905/
|
|
Summary: www-client/links vulnerablitiy in smb:// URL handling (CVE-2006-5925)
|
|
Keywords:
|
|
Status Whiteboard: B3? [glsa]
|
|
Opened: 2006-12-03 15:38 0000
|
Hi,
please bump www-client/links to pre26.
In the changelog, there's also a entry about a severe security bug
http://links.twibright.com/download/ChangeLog
Tue Nov 28 23:13:38 MET 2006 mikulas:
Fixed severe security bug: '"' and ';' in smb:// url could be used for
remote command execution.
Thanks!
Thanks, 2.1_pre26 in cvs.
Security, I believe you take it from here :-).
Cheers
hard to rate this... B3 might be closes
from Secunia:
Successful exploitation allows exposure of sensitive information or
manipulation of data, but requires that the user visits a malicious "smb://"
URL or gets redirected to such an URL by a malicious URL, and that the user has
the smbclient program installed.
security please vote
I tend to vote NO. How often do you use lins for smb:// stuff?
I guess it's not whether you would use it, but you could be enticed to use it
by a malicious site. If this works for <IMG SRC="smb://..."> tags for example,
you'll be screwed. (Note that I don't know whether it does, I just remember a
bug like that in firefox.) Redirection will not automatically screw you, though
(at least not in the default conf).
I tend to vote yes. I admit it's "thin", but it's also bad ^_^
i vote yes... and isn't it a B2 instead of B3 ?
ok, agreed... let's have a GLSA