Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-5953

Опубликовано: 03 апр. 2019
Источник: redhat
CVSS3: 8.8

Описание

Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.

A buffer overflow flaw was found in the GNU Wget in version 1.20.1 and earlier when processing Internationalized Resource Identifiers. This flaw allows an attacker to execute arbitrary code or cause a denial of service.

Отчет

This issue did not affect the versions of wget as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the versions of wget as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5wgetNot affected
Red Hat Enterprise Linux 6wgetNot affected
Red Hat Enterprise Linux 7wgetFixedRHSA-2019:122814.05.2019
Red Hat Enterprise Linux 7.4 Advanced Update SupportwgetFixedRHSA-2019:316823.10.2019
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportwgetFixedRHSA-2019:316823.10.2019
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionswgetFixedRHSA-2019:316823.10.2019
Red Hat Enterprise Linux 7.5 Extended Update SupportwgetFixedRHSA-2019:297908.10.2019
Red Hat Enterprise Linux 8wgetFixedRHSA-2019:098307.05.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1695679wget: do_conversion() heap-based buffer overflow vulnerability

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.

CVSS3: 9.8
nvd
больше 6 лет назад

Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.

CVSS3: 9.8
debian
больше 6 лет назад

Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers ...

suse-cvrf
почти 7 лет назад

Security update for wget

suse-cvrf
почти 7 лет назад

Security update for wget

8.8 High

CVSS3