GLSA: wget

From: Daniel Ahlberg (aliz@gentoo.org)
Date: 12/20/02

  • Next message: Mischa Krilov: "Re: Foundstone Research Labs Advisory - Multiple Exploitable Buff er Overflows in Winamp (fwd)"
    From: Daniel Ahlberg <aliz@gentoo.org>
    Date: Fri, 20 Dec 2002 18:16:15 +0100
    To: bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200212-7
    - - --------------------------------------------------------------------

    PACKAGE : wget
    SUMMARY : directory traversal
    DATE    : 2002-12-20 17:12 UTC
    EXPLOIT : remote

    - - --------------------------------------------------------------------

    Quote from advisory

    "A malicious server could potentially overwrite key files to cause a
    denial of service or, in some cases, gain privileges by modifying
    executable files. The risk is mitigated because non-default
    configurations are primarily affected, and the user must be convinced
    to access the malicious server. However, web-based clients may be
    more easily exploited."

    Read the full advisory at
    http://marc.theaimsgroup.com/?l=bugtraq&m=103962838628940&w=2 recommended that all Gentoo Linux users who are running

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    net-misc/wget-1.8.2-r1 and earlier update their systems as follows:

    emerge rsync
    emerge wget
    emerge clean

    - - --------------------------------------------------------------------
    aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)

    iD8DBQE+A1BVfT7nyhUpoZMRAitfAJ0ZuwvlTRZnBP9rzfRPE51L7Qm3MwCfUXLn
    4QPk2v8r54aB+53CPAwIFhk=
    =RLsN
    -----END PGP SIGNATURE-----



    Relevant Pages

    • [Full-Disclosure] GLSA: wget
      ... GENTOO LINUX SECURITY ANNOUNCEMENT 200212-7 ... PACKAGE: wget ... to access the malicious server. ... Read the full advisory at ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: netscape-flash (200303-9)
      ... GENTOO LINUX SECURITY ANNOUNCEMENT 200303-9 ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge netscape-flash ...
      (Full-Disclosure)
    • GLSA: apache (200304-01)
      ... "Remote exploitation of a memory leak in the Apache HTTP Server causes the ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ...
      (Bugtraq)
    • [Full-Disclosure] GLSA: apache (200304-01)
      ... "Remote exploitation of a memory leak in the Apache HTTP Server causes the ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: man (200303-13)
      ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge sync ...
      (Full-Disclosure)