Wget could be made to inject arbitrary cookie values.. =========================================================================Ubuntu Security Notice USN-3643-2 May 09, 2018 wget vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Wget could be made to inject arbitrary cookie values. Software Description: - wget: retrieves files from the web Details: USN-3643-1 fixed a vulnerability in Wget. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that Wget incorrectly handled certain inputs. An attacker could possibly use this to inject arbitrary cookie values. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: wget 1.13.4-2ubuntu1.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3643-2 https://ubuntu.com/security/notices/USN-3643-1 CVE-2018-0494 . Security flaw in Wget addressed in Ubuntu 12.04 ESM update to eliminate cookie manipulation concerns. Ensure your system is updated.. Wget Vulnerability, Ubuntu Security Update, Cookie Injection, USN 3643-2. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.