Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Links, ELinks 'smbclient' Remote Command Execution Vulnerability

Links and ELinks are prone to a remote command-execution vulnerability because the applications fail to properly process website data containing 'smb' commands.

An attacker can exploit this issue to execute arbitrary 'smb' commands on a victim computer. This may help the attacker compromise the application and the underlying system; other attacks are also possible.

Links 1.00pre12 and ELinks 0.11.1 are vulnerable; other versions may also be affected.

NOTE: This vulnerability may be exploited only if 'smbclient' is installed on a target computer.







 

Privacy Statement
Copyright 2009, SecurityFocus