Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1250
    posted: 08/27/08
  • NSM Daily Update #1250
    posted: 08/27/08
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1250
    posted: 08/27/08
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1227
    posted: 08/27/08
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 08/26/08

Title: SmbClientParser Perl Module Remote Command Execution Vulnerability

Severity: HIGH

Description:

The SmbClientParser Perl module is an API used to access Samba resources using 'smbclient'.

The module is prone to a remote command-execution vulnerability because it fails to sufficiently sanitize user-supplied data. An attacker could exploit this issue by enticing an unsuspecting user to use a tool created with this module to scan a shared folder that contains a folder with a specially crafted name. The name of the folder can be used to execute arbitrary commands on the victim's computer.

Successfully exploiting this issue will allow an attacker to execute arbitrary commands with the privileges of the user running applications that use the module.

Filesys::SmbClientParser 2.7 is vulnerable; other versions may also be affected.

Affected Products:

  • Alain Barbet Filesys::SmbClientParser 2.7

References: