Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade elinksUpgrade links2 | Jul 30, 2024 | Nov 15, 2006 |
| Gentoo Linux | — | Upgrade www-client/elinks.Upgrade www-client/links. | Oct 30, 2017 | Nov 15, 2006 |
| Ubuntu | — | Upgrade elinksUpgrade elinks-lite | Nov 8, 2024 | Nov 15, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub