Описание
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
It was found that wget used a file name provided by the server for the downloaded file when following a HTTP redirect to a FTP server resource. This could cause wget to create a file with a different name than expected, possibly allowing the server to execute arbitrary code on the client.
Меры по смягчению последствий
Use wget with "-O" option to explicitly specify the output filename.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | wget | Will not fix | ||
Red Hat Enterprise Linux 6 | wget | Will not fix | ||
Red Hat Enterprise Linux 7 | wget | Fixed | RHSA-2016:2587 | 03.11.2016 |
Показывать по
Дополнительная информация
Статус:
7 High
CVSS3
6.8 Medium
CVSS2
Связанные уязвимости
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
GNU wget before 1.18 allows remote servers to write to arbitrary files ...
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
ELSA-2016-2587: wget security and bug fix update (MODERATE)
7 High
CVSS3
6.8 Medium
CVSS2