Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 12.04 ESM USN-3464-2 Critical Wget Denial Of Service Threat

ubuntu
Calendar Grey October 30, 2017
Scroller Ubuntu
Ubuntu Security Notice USN-3465-1 addresses weaknesses in OpenSSL, mitigating risks of data breaches and unauthorized access.
Several security issues were fixed in Wget.

Summary

Several security issues were fixed in Wget.

Software Description:

- wget: retrieves files from the web

Details:

USN-3464-1 fixed several vulnerabilities in Wget. This update

provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that

 Wget incorrectly handled certain HTTP responses. A remote attacker

 could use this issue to cause Wget to crash, resulting in a denial of

 service, or possibly execute arbitrary code. 

 (CVE-2017-13089, CVE 2017-13090)

 Dawid Golunski discovered that Wget incorrectly handled recursive or

 mirroring mode. A remote attacker could possibly use this issue to

 bypass intended access list restrictions. (CVE-2016-7098)

 Orange Tsai discovered that Wget incorrectly handled CRLF sequences in

 HTTP headers. A remote attacker could possibly use this issue to

 inject arbitrary HTTP headers. (CVE-2017-6508)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  wget                            1.13.4-2ubuntu1.5

In general, a standard system update will make all the necessary
changes.

References

 

 

  CVE-2016-7098, CVE-2017-13089, CVE-2017-13090, CVE-2017-6508

Severity
critical
Lowest
Low
Medium
High
Critical

October 30, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.