Description
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
Affected products
- gnu / wget1.5.3 – 1.5.3
- gnu / wget1.6 – 1.6
- gnu / wget1.7 – 1.7
- gnu / wget1.7.1 – 1.7.1
- gnu / wget1.8 – 1.8
- gnu / wget1.8.1 – 1.8.1
- gnu / wget1.8.2 – 1.8.2
- gnu / wget1.9 – 1.9
- gnu / wget1.9.1 – 1.9.1
References
- MAILING_LISThttp://marc.info/?l=wget&m=108483270227139&w=2
- MISChttp://www.redhat.com/support/errata/RHSA-2005-771.html
- VENDOR_ADVISORYhttps://usn.ubuntu.com/145-1/
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9830
- VENDOR_ADVISORYhttp://secunia.com/advisories/17399
- MAILING_LISThttp://marc.info/?l=wget&m=108482747906833&w=2
- MISChttp://www.securityfocus.com/bid/10361
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/16167
- MAILING_LISThttp://marc.info/?l=bugtraq&m=108481268725276&w=2
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:204