SB2016070507 - Security Features in wget (Alpine package)
Published: July 5, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security Features (CVE-ID: CVE-2016-4971)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=f697ff8d2dd6ecbdd7acc4285c87f9eeb5cbbe9c
- https://git.alpinelinux.org/aports/commit/?id=55878e350bf069ec499d2f5199cf5e8b80778ad9
- https://git.alpinelinux.org/aports/commit/?id=77d0563f61e1adaf078aa318d6da7972881e3c18
- https://git.alpinelinux.org/aports/commit/?id=b9a9e933c28f5ae35d7ecdb12cbed584c2d10c4d