Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Gentoo Linux GLSA 200910-01 Normal: Wget Man-in-the-Middle Risk

gentoo
Calendar Grey October 20, 2009
Scroller Gentoo
Users of Curl are required to update because of a medium severity flaw in certificate management that may lead to man-in-the-middle vulnerabilities.
An error in the X.509 certificate handling of Wget might enable remote attackers to conduct man-in-the-middle attacks.

Summary

Gentoo Linux Security Advisory GLSA 200910-01 https://security.gentoo.org/ Severity: Normal Title: Wget: Certificate validation error Date: October 20, 2009 Bugs: #286058 ID: 200910-01

Synopsis ======= An error in the X.509 certificate handling of Wget might enable remote attackers to conduct man-in-the-middle attacks.
Background ========= GNU Wget is a free software package for retrieving files using HTTP, HTTPS and FTP, the most widely-used Internet protocols.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/wget < 1.12 >= 1.12
========== The vendor reported that Wget does not properly handle Common Name (CN) fields in X.509 certificates ...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround