[Bug 14442] Shell command injection vulnerability in mount.cifs

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



https://bugzilla.samba.org/show_bug.cgi?id=14442

--- Comment #7 from Marcus Meissner <meissner@xxxxxxx> ---
Looks like a valid CVE scenario. (untrusted users might be asked to input their
smb sharwe username which is then passed unfiltered into this kind of
mount.cifs construct)

additionaly to the proposed fixes, perhaps also check for valid characters and
abort if you encounter an invalid one.

-- 
You are receiving this mail because:
You are the QA Contact for the bug.



[Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite News]     [Linux Kernel]     [Linux SCSI]

  Powered by Linux