Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Gentoo: 202305-12 Critical Alert: Curl Path Disclosure Vulnerability

gentoo
Calendar Grey December 20, 2002
Dist Gentoo Esm H88
- -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNC
A malicious server could potentially overwrite key files to cause a denial of service or, in some cases, gain privileges by modifying executable files.

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200212-7
- --------------------------------------------------------------------
DATE    : 2002-12-20 17:12 UTC

- --------------------------------------------------------------------
Quote from advisory
"A malicious server could potentially overwrite key files to cause a denial of service or, in some cases, gain privileges by modifying executable files. The risk is mitigated because non-default configurations are primarily affected, and the user must be convinced to access the malicious server. However, web-based clients may be more easily exploited."
Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=103962838628940&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running net-misc/wget-1.8.2-r1 and earlier update their systems as follows:
emerge rsync emerge wget emerge clean
...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : wget
SUMMARY : directory traversal
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here