Description
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1226-1 | New links packages fix arbitrary shell command execution |
Debian DSA |
DSA-1228-1 | New elinks packages fix arbitrary shell command execution |
Debian DSA |
DSA-1240-1 | New links2 packages fix arbitrary shell command execution |
Ubuntu USN |
USN-851-1 | Elinks vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T20:12:30.612Z
Reserved: 2006-11-15T00:00:00.000Z
Link: CVE-2006-5925
No data.
Status : Modified
Published: 2006-11-15T19:07:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2006-5925
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN