WGet Insecure File Creation Race Condition Vulnerability
BID:10361
Info
WGet Insecure File Creation Race Condition Vulnerability
| Bugtraq ID: | 10361 |
| Class: | Race Condition Error |
| CVE: |
CVE-2004-2014 |
| Remote: | No |
| Local: | Yes |
| Published: | May 17 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery of this vulnerability has been credited to Hugo "Vázquez" "Caramés" <[email protected]>. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux 10 F... Turbolinux Home Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 GNU wget 1.9.1 GNU wget 1.9 GNU wget 1.8.2 GNU wget 1.8.1 GNU wget 1.8 GNU wget 1.7.1 GNU wget 1.7 GNU wget 1.6 GNU wget 1.5.3 |
| Not Vulnerable: | |
Discussion
WGet Insecure File Creation Race Condition Vulnerability
The 'wget' utility has been reported prone to a race-condition vulnerability. The issue exists because wget doesn't lock files that it creates and writes to during file downloads.
A local attacker may exploit this condition to corrupt files with the privileges of the victim who is running the vulnerable version of wget.
The 'wget' utility has been reported prone to a race-condition vulnerability. The issue exists because wget doesn't lock files that it creates and writes to during file downloads.
A local attacker may exploit this condition to corrupt files with the privileges of the victim who is running the vulnerable version of wget.
Exploit / POC
WGet Insecure File Creation Race Condition Vulnerability
The following proof of concept exploit has been supplied:
The following proof of concept exploit has been supplied:
Solution / Fix
WGet Insecure File Creation Race Condition Vulnerability
Solution:
Please see the referenced advisories for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
GNU wget 1.7
GNU wget 1.8.2
GNU wget 1.9.1
Solution:
Please see the referenced advisories for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
GNU wget 1.7
-
TurboLinux wget-1.10-1.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/7/upd ates/RPMS/wget-1.10-1.i586.rpm -
TurboLinux wget-1.10-1.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 7/updates/RPMS/wget-1.10-1.i586.rpm
GNU wget 1.8.2
-
TurboLinux wget-1.10-1.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/wget-1.10-1.i586.rpm -
TurboLinux wget-1.10-1.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/10/up dates/RPMS/wget-1.10-1.i586.rpm -
TurboLinux wget-1.10-1.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Server/8/upd ates/RPMS/wget-1.10-1.i586.rpm -
TurboLinux wget-1.10-1.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Workstation/ 8/updates/RPMS/wget-1.10-1.i586.rpm
GNU wget 1.9.1
-
Ubuntu wget_1.9.1-10ubuntu2.2_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_amd64.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_i386.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_powerpc.deb -
Ubuntu wget_1.9.1-10ubuntu2.1_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.1_amd64.deb -
Ubuntu wget_1.9.1-10ubuntu2.1_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.1_i386.deb -
Ubuntu wget_1.9.1-10ubuntu2.1_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.1_powerpc.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_amd64.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_i386.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_powerpc.deb -
Ubuntu wget_1.9.1-4ubuntu0.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-4ubuntu0 .1_amd64.deb -
Ubuntu wget_1.9.1-4ubuntu0.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-4ubuntu0 .1_i386.deb -
Ubuntu wget_1.9.1-4ubuntu0.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-4ubuntu0 .1_powerpc.deb
References
WGet Insecure File Creation Race Condition Vulnerability
References:
References:
- GNU Homepage (GNU)
- RHSA-2005:771-10 - wget security update (RedHat)
- Wget race condition vulnerability ( Hugo "Vázquez" "Caramés"
)