GNU WGet Multiple Remote Vulnerabilities
BID:11871
Info
GNU WGet Multiple Remote Vulnerabilities
| Bugtraq ID: | 11871 |
| Class: | Design Error |
| CVE: |
CVE-2004-1487 CVE-2004-1488 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2004 12:00AM |
| Updated: | Jul 17 2006 06:13PM |
| Credit: | Discovery of these issues is credited to Jan Minar <[email protected]>. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Home Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Trustix Secure Linux 2.2 Trustix Secure Linux 2.1 Trustix Secure Enterprise Linux 2.0 SuSE SUSE Linux Enterprise Server 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 SuSE Linux 8.1 SuSE Linux 8.0 i386 SuSE Linux 8.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Personal 10.1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 GNU wget 1.9.1 GNU wget 1.9 GNU wget 1.8.2 GNU wget 1.8.1 GNU wget 1.8 |
| Not Vulnerable: | |
Discussion
GNU WGet Multiple Remote Vulnerabilities
Multiple remote vulnerabilities reportedly affect GNU wget. These issues are due to the application's failure to properly sanitize user-supplied input and to properly validate the presence of files before writing to them. The issues include:
- a potential directory-traversal issue
- an arbitrary file-overwriting vulnerability
- a weakness caused by the application's failure to filter potentially malicious characters from server-supplied input.
Via a malicious server, an attacker may exploit these issues to arbitrarily overwrite files within the current directory and potentially outside of it. This may let the attacker corrupt files, cause a denial of service, and possibly launch further attacks against the affected computer. Overwriting of files would take place with the privileges of the user that activates the vulnerable application.
Multiple remote vulnerabilities reportedly affect GNU wget. These issues are due to the application's failure to properly sanitize user-supplied input and to properly validate the presence of files before writing to them. The issues include:
- a potential directory-traversal issue
- an arbitrary file-overwriting vulnerability
- a weakness caused by the application's failure to filter potentially malicious characters from server-supplied input.
Via a malicious server, an attacker may exploit these issues to arbitrarily overwrite files within the current directory and potentially outside of it. This may let the attacker corrupt files, cause a denial of service, and possibly launch further attacks against the affected computer. Overwriting of files would take place with the privileges of the user that activates the vulnerable application.
Exploit / POC
GNU WGet Multiple Remote Vulnerabilities
The following exploit has been made available:
The following exploit has been made available:
Solution / Fix
GNU WGet Multiple Remote Vulnerabilities
Solution:
Please see the referenced advisories for more information.
GNU wget 1.8.2
GNU wget 1.9.1
Solution:
Please see the referenced advisories for more information.
GNU wget 1.8.2
-
Mandriva wget-1.8.2-3.2.C21mdk.i586.rpm
Corporate Server 2.1
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva wget-1.8.2-3.2.C21mdk.x86_64.rpm
Corporate Server 2.1/X86_64
http://www1.mandrivalinux.com/en/ftp.php3
GNU wget 1.9.1
-
Mandriva wget-1.9.1-4.1.100mdk.amd64.rpm
Mandrakelinux 10.0/AMD64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva wget-1.9.1-4.1.100mdk.i586.rpm
Mandrakelinux 10.0
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva wget-1.9.1-4.2.101mdk.i586.rpm
Mandrakelinux 10.1
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva wget-1.9.1-4.2.101mdk.x86_64.rpm
Mandrakelinux 10.1/X86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva wget-1.9.1-4.2.C30mdk.i586.rpm
Corporate 3.0
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva wget-1.9.1-4.2.C30mdk.x86_64.rpm
Corporate 3.0/X86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva wget-1.9.1-5.1.102mdk.i586.rpm
Mandrakelinux 10.2
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva wget-1.9.1-5.1.102mdk.x86_64.rpm
Mandrakelinux 10.2/X86_64
http://www1.mandrivalinux.com/en/ftp.php3 -
Ubuntu wget_1.9.1-10ubuntu2.2_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_amd64.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_i386.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_powerpc.deb -
Ubuntu wget_1.9.1-10ubuntu2.1_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.1_amd64.deb -
Ubuntu wget_1.9.1-10ubuntu2.1_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.1_i386.deb -
Ubuntu wget_1.9.1-10ubuntu2.1_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.1_powerpc.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_amd64.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_i386.deb -
Ubuntu wget_1.9.1-10ubuntu2.2_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-10ubuntu 2.2_powerpc.deb -
Ubuntu wget_1.9.1-4ubuntu0.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-4ubuntu0 .1_amd64.deb -
Ubuntu wget_1.9.1-4ubuntu0.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-4ubuntu0 .1_i386.deb -
Ubuntu wget_1.9.1-4ubuntu0.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.9.1-4ubuntu0 .1_powerpc.deb
References
GNU WGet Multiple Remote Vulnerabilities
References:
References: