Bug#399187: CVE-2006-5925: Links "smb" Protocol File Upload/Download Vulnerability

2006-11-27 Thread Julien Cristau
On Mon, Nov 27, 2006 at 02:25:32 +0100, Julien Cristau wrote: > Hi, the attached patch disables smb support in links and thus fixes this > issue. > An NMU has been uploaded today with the patch I attached to my previous mail. Cheers, Julien signature.asc Description: Digital signature

Bug#399187: CVE-2006-5925: Links "smb" Protocol File Upload/Download Vulnerability

2006-11-26 Thread Julien Cristau
tags 399187 patch kthxbye On Sat, Nov 18, 2006 at 12:59:57 +0100, Stefan Fritsch wrote: > A vulnerability has been found in links: > Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed > allows remote attackers to execute arbitrary code via shell > metacharacters in an smb:// UR

Bug#399187: CVE-2006-5925: Links "smb" Protocol File Upload/Download Vulnerability

2006-11-18 Thread Stefan Fritsch
package: links severity: grave tags: security A vulnerability has been found in links: Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.