Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

SUSE-SU-2016:2358-1

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 23 сСнт. 2016
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: suse-cvrf

ОписаниС

Security update for wget

This update for wget fixes the following issues:

  • CVE-2016-4971: A HTTP to FTP redirection file name confusion vulnerability was fixed. (bsc#984060).

  • CVE-2016-7098: A potential race condition was fixed by creating files with .tmp ext and making them accessible to the current user only. (bsc#995964)

Bug fixed:

  • Wget failed with basicauth: Failed writing HTTP request: Bad file descriptor (bsc#958342)

Бписок ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ²

SUSE Linux Enterprise Point of Sale 11 SP3
wget-1.11.4-1.32.1
SUSE Linux Enterprise Server 11 SP3-LTSS
wget-1.11.4-1.32.1
wget-openssl1-1.11.4-1.32.1
SUSE Linux Enterprise Server 11 SP3-TERADATA
wget-1.11.4-1.32.1
wget-openssl1-1.11.4-1.32.1
SUSE Linux Enterprise Server 11 SP4
wget-1.11.4-1.32.1
SUSE Linux Enterprise Server 11-SECURITY
wget-openssl1-1.11.4-1.32.1
SUSE Linux Enterprise Server for SAP Applications 11 SP4
wget-1.11.4-1.32.1
SUSE Manager 2.1
wget-1.11.4-1.32.1
SUSE Manager Proxy 2.1
wget-1.11.4-1.32.1
SUSE OpenStack Cloud 5
wget-1.11.4-1.32.1

ОписаниС

GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
SUSE Linux Enterprise Point of Sale 11 SP3:wget-1.11.4-1.32.1
SUSE Linux Enterprise Server 11 SP3-LTSS:wget-1.11.4-1.32.1
SUSE Linux Enterprise Server 11 SP3-LTSS:wget-openssl1-1.11.4-1.32.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:wget-1.11.4-1.32.1

Бсылки

ОписаниС

Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
SUSE Linux Enterprise Point of Sale 11 SP3:wget-1.11.4-1.32.1
SUSE Linux Enterprise Server 11 SP3-LTSS:wget-1.11.4-1.32.1
SUSE Linux Enterprise Server 11 SP3-LTSS:wget-openssl1-1.11.4-1.32.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:wget-1.11.4-1.32.1

Бсылки
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ SUSE-SU-2016:2358-1