Title: SmbClientParser Perl Module Remote Command Execution Vulnerability
Severity: HIGH
Description:
The SmbClientParser Perl module is an API used to access Samba resources using 'smbclient'.
The module is prone to a remote command-execution vulnerability because it fails to sufficiently sanitize user-supplied data. An attacker could exploit this issue by enticing an unsuspecting user to use a tool created with this module to scan a shared folder that contains a folder with a specially crafted name. The name of the folder can be used to execute arbitrary commands on the victim's computer.
Successfully exploiting this issue will allow an attacker to execute arbitrary commands with the privileges of the user running applications that use the module.
Filesys::SmbClientParser 2.7 is vulnerable; other versions may also be affected.
Affected Products:
- Alain Barbet Filesys::SmbClientParser 2.7
References:
- Alain Barbet: Filesys::SmbClientParser CPAN Page
