GNU Wget FTP_Syst Function Remote Denial of Service Vulnerability
BID:21650
Info
GNU Wget FTP_Syst Function Remote Denial of Service Vulnerability
| Bugtraq ID: | 21650 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-6719 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2006 12:00AM |
| Updated: | Jan 31 2007 09:38PM |
| Credit: | Federico L. Bossi Bonin is credited with the discovery of this vulnerability. |
| Vulnerable: |
Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Operating System Enterprise Server 2.0 rPath rPath Linux 1 Redhat Fedora Core6 Redhat Fedora Core5 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 GNU wget 1.10.2 GNU wget 1.10.1 GNU wget 1.10 GNU wget 1.9.1 GNU wget 1.9 GNU wget 1.8.2 GNU wget 1.8.1 GNU wget 1.8 GNU wget 1.7.1 GNU wget 1.7 GNU wget 1.6 GNU wget 1.5.3 |
| Not Vulnerable: | |
Discussion
GNU Wget FTP_Syst Function Remote Denial of Service Vulnerability
GNU Wget is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to crash the application, denying further service to legitimate users.
Version 1.10.2 is vulnerable; other versions may also be affected.
GNU Wget is prone to a remote denial-of-service vulnerability.
Exploiting this issue allows remote attackers to crash the application, denying further service to legitimate users.
Version 1.10.2 is vulnerable; other versions may also be affected.
Exploit / POC
GNU Wget FTP_Syst Function Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
GNU Wget FTP_Syst Function Remote Denial of Service Vulnerability
Solution:
Fedora Updates FEDORA-2007-037 for Fedora Core 5 and FEDORA-2007-043 for Fedora Core 6 are available; please see the reference section for details.
GNU wget 1.10
GNU wget 1.10.2
GNU wget 1.8.1
GNU wget 1.9.1
Solution:
Fedora Updates FEDORA-2007-037 for Fedora Core 5 and FEDORA-2007-043 for Fedora Core 6 are available; please see the reference section for details.
GNU wget 1.10
-
Mandriva wget-1.10-1.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.10-1.2.20060mdk.src.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.10-1.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.10-1.2.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.10-1.2.20060mlcs4.src.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.10-1.2.20060mlcs4.x86_64.rpm
Corporate 4.0:
http://www.mandriva.com/en/download
GNU wget 1.10.2
-
Mandriva wget-1.10.2-3.1mdv2007.0.i586.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.10.2-3.1mdv2007.0.src.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.10.2-3.1mdv2007.0.x86_64.rpm
Mandriva Linux 2007.0:
http://www.mandriva.com/en/download
GNU wget 1.8.1
-
Mandriva wget-1.9.1-4.4.M20mdk.i586.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.9.1-4.4.M20mdk.src.rpm
Multi Network Firewall 2.0:
http://www.mandriva.com/en/download
GNU wget 1.9.1
-
Mandriva wget-1.9.1-4.4.C30mdk.i586.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.9.1-4.4.C30mdk.src.rpm
Corporate 3.0:
http://www.mandriva.com/en/download -
Mandriva wget-1.9.1-4.4.C30mdk.x86_64.rpm
Corporate 3.0:
http://www.mandriva.com/en/download
References
GNU Wget FTP_Syst Function Remote Denial of Service Vulnerability
References:
References: