All of lore.kernel.org
 help / color / mirror / Atom feed
* [Bug 14442] New: Shell command injection vulnerability in mount.cifs
@ 2020-07-16 17:50 samba-bugs
  2020-07-16 22:40 ` [Bug 14442] " samba-bugs
                   ` (17 more replies)
  0 siblings, 18 replies; 19+ messages in thread
From: samba-bugs @ 2020-07-16 17:50 UTC (permalink / raw)
  To: cifs-qa

https://bugzilla.samba.org/show_bug.cgi?id=14442

            Bug ID: 14442
           Summary: Shell command injection vulnerability in mount.cifs
           Product: CifsVFS
           Version: 2.4
          Hardware: All
                OS: Linux
            Status: NEW
          Severity: major
          Priority: P5
         Component: kernel fs
          Assignee: sfrench@samba.org
          Reporter: vadim@mbdsys.com
        QA Contact: cifs-qa@samba.org
  Target Milestone: ---

mount.cifs command is using "popen" library call in get_password 
which allows for shell command execution. 
Example:

sudo /bin/mount -t cifs -o username="test \$(id)" //1 /mnt

-- 
You are receiving this mail because:
You are the QA Contact for the bug.

^ permalink raw reply	[flat|nested] 19+ messages in thread

end of thread, other threads:[~2020-07-28 15:56 UTC | newest]

Thread overview: 19+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-07-16 17:50 [Bug 14442] New: Shell command injection vulnerability in mount.cifs samba-bugs
2020-07-16 22:40 ` [Bug 14442] " samba-bugs
2020-07-17  3:50 ` samba-bugs
2020-07-17 14:51 ` samba-bugs
2020-07-17 15:02 ` samba-bugs
2020-07-17 17:21 ` samba-bugs
2020-07-18 14:14 ` samba-bugs
2020-07-20 17:35 ` samba-bugs
2020-07-23  5:35 ` samba-bugs
2020-07-23  8:18 ` samba-bugs
2020-07-23  9:41 ` samba-bugs
2020-07-24 14:52 ` [Bug 14442] CVE-2020-14342: " samba-bugs
2020-07-27 11:33 ` samba-bugs
2020-07-27 11:33 ` samba-bugs
2020-07-27 11:41 ` samba-bugs
2020-07-27 11:47 ` samba-bugs
2020-07-27 21:54 ` samba-bugs
2020-07-28 15:56 ` samba-bugs
2020-07-28 15:56 ` samba-bugs

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.