Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian: DSA-209-1 Critical: Wget Directory Traversal and Buffer Overflow

debian
Calendar Grey December 13, 2002
Debian Logo
Critical advisory on wget's buffer overflow and directory traversal risks. Essential security updates recommended for Debian.
There are two buffer overflow vulnerabilites that have been found in the wget package.

Summary

Package : wget
Problem type : directory traversal
buffer overflow
Debian-specific: no
CVEs : CAN-2002-1344

Two problems have been found in the wget package as distributed in
Debian GNU/Linux:

* Stefano Zacchiroli found a buffer overrun in the url_filename function,
which would make wget segfault on very long URLs

* Steven M. Christey discovered that wget did not verify the FTP server
response to a NLST command: it must not contain any directory information,
since that can be used to make a FTP client overwrite arbitrary files.

Both problems have been fixed in version 1.5.3-3.1 for Debian GNU/Linux
2.2/potato and version 1.8.1-6.1 for Debian GNU/Linux 3.0/woody.

------------------------------------------------------------------------

Obtaining updates:

By hand:
wget URL
will fetch the file for you.
dpkg -i FILENAME.deb
will install the fetched file.

With apt:
deb Debian -- Security Information stable/updates main
added to /...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here