WGet NLST Client Side File Overwriting Vulnerability
BID:6352
Info
WGet NLST Client Side File Overwriting Vulnerability
| Bugtraq ID: | 6352 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1344 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2002 12:00AM |
| Updated: | Jul 11 2009 07:16PM |
| Credit: | Vulnerability discovery credited to Steve Christey. |
| Vulnerable: |
Sun Cobalt RaQ XTR GNU wget 1.8.2 GNU wget 1.8.1 GNU wget 1.8 GNU wget 1.7.1 GNU wget 1.7 GNU wget 1.6 GNU wget 1.5.3 |
| Not Vulnerable: | |
Discussion
WGet NLST Client Side File Overwriting Vulnerability
wget is a freely available, open source FTP utility. It is included with many Unix and Linux operating systems.
wget does not properly handle some types of server responses. When a NLST response is received from an FTP server, RFC specifications require that clients check the input to see if it contains directory information. wget does not properly check this information, which may allow a remote FTP server to overwrite files on the client system.
wget is a freely available, open source FTP utility. It is included with many Unix and Linux operating systems.
wget does not properly handle some types of server responses. When a NLST response is received from an FTP server, RFC specifications require that clients check the input to see if it contains directory information. wget does not properly check this information, which may allow a remote FTP server to overwrite files on the client system.
Exploit / POC
WGet NLST Client Side File Overwriting Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
WGet NLST Client Side File Overwriting Vulnerability
Solution:
Sun have released a security update to address this issue in the RAQ XTR. Please see references section for further details. A fix is linked below.
RedHat has released advisory RHSA-2002:229-10 to address this issue.
Mandrake has released a security advisory (MDKSA-2002:86) containing fixes.
Debian has made fixes available. See referenced advisory for additional details.
Gentoo has released an advisory and fix for this issue. Please see the attached advisory for details on obtaining and applying fixes.
SCO has made fixes for Caldera Linux available.
Immunix has released a security advisory (IMNX-2003-7+-011-01) containing fixes to address this issue. Users are advised to upgrade as soon as possible.
Fixes available:
Sun Cobalt RaQ XTR
GNU wget 1.5.3
GNU wget 1.7.1
GNU wget 1.8.1
GNU wget 1.8.2
Solution:
Sun have released a security update to address this issue in the RAQ XTR. Please see references section for further details. A fix is linked below.
RedHat has released advisory RHSA-2002:229-10 to address this issue.
Mandrake has released a security advisory (MDKSA-2002:86) containing fixes.
Debian has made fixes available. See referenced advisory for additional details.
Gentoo has released an advisory and fix for this issue. Please see the attached advisory for details on obtaining and applying fixes.
SCO has made fixes for Caldera Linux available.
Immunix has released a security advisory (IMNX-2003-7+-011-01) containing fixes to address this issue. Users are advised to upgrade as soon as possible.
Fixes available:
Sun Cobalt RaQ XTR
-
Sun RaQXTR-All-Security-1.0.1-16342.pkg
http://ftp.cobalt.sun.com/pub/packages/raqxtr/eng/RaQXTR-All-Security- 1.0.1-16342.pkg
GNU wget 1.5.3
-
Debian wget_1.5.3-3.1_alpha.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/w/wget/wget_1.5.3-3.1_alp ha.deb -
Debian wget_1.5.3-3.1_arm.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/w/wget/wget_1.5.3-3.1_arm .deb -
Debian wget_1.5.3-3.1_i386.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/w/wget/wget_1.5.3-3.1_i38 6.deb -
Debian wget_1.5.3-3.1_m68k.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/w/wget/wget_1.5.3-3.1_m68 k.deb -
Debian wget_1.5.3-3.1_powerpc.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/w/wget/wget_1.5.3-3.1_pow erpc.deb -
Debian wget_1.5.3-3.1_sparc.deb
Debian GNU/Linux 2.2 alias potato
http://security.debian.org/pool/updates/main/w/wget/wget_1.5.3-3.1_spa rc.deb
GNU wget 1.7.1
-
SCO wget-1.7.1-3.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2003-003.0/R PMS/wget-1.7.1-3.i386.rpm -
SCO wget-1.7.1-3.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2003-00 3.0/RPMS/wget-1.7.1-3.i386.rpm -
SCO wget-1.7.1-3.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2003-003.0/RPM S/wget-1.7.1-3.i386.rpm -
SCO wget-1.7.1-3.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2003-003. 0/RPMS/wget-1.7.1-3.i386.rpm
GNU wget 1.8.1
-
Debian wget_1.8.1-6.1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_alp ha.deb -
Debian wget_1.8.1-6.1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_arm .deb -
Debian wget_1.8.1-6.1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_hpp a.deb -
Debian wget_1.8.1-6.1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_i38 6.deb -
Debian wget_1.8.1-6.1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_ia6 4.deb -
Debian wget_1.8.1-6.1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_m68 k.deb -
Debian wget_1.8.1-6.1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_mip s.deb -
Debian wget_1.8.1-6.1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_pow erpc.deb -
Debian wget_1.8.1-6.1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_s39 0.deb -
Debian wget_1.8.1-6.1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/w/wget/wget_1.8.1-6.1_spa rc.deb
GNU wget 1.8.2
-
Conectiva wget-1.8.2-146.i586.rpm
ftp://ul.conectiva.com.br/updates/1.0/i386/RPMS.core/wget-1.8.2-146.i5 86.rpm -
Conectiva wget-1.8.2-1U60_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/wget-1.8.2-1U60_1cl.i386. rpm -
Conectiva wget-1.8.2-1U70_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/wget-1.8.2-1U70_1cl.i386. rpm -
Conectiva wget-1.8.2-1U80_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/wget-1.8.2-1U80_1cl.i386.rp m -
Immunix wget-1.8.2-4.70_imnx_3.i386.rpm
http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/wget-1.8.2-4.70_ imnx_3.i386.rpm -
Mandrake wget-1.8.2-3.1mdk.i586.rpm
Linux-Mandrake 7.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake wget-1.8.2-3.1mdk.i586.rpm
Mandrake Linux 8.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake wget-1.8.2-3.1mdk.i586.rpm
Mandrake Linux 8.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake wget-1.8.2-3.1mdk.i586.rpm
Mandrake Linux 8.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake wget-1.8.2-3.1mdk.i586.rpm
Mandrake Linux 9.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake wget-1.8.2-3.1mdk.i586.rpm
Single Network Firewall 7.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake wget-1.8.2-3.1mdk.ia64.rpm
Mandrake Linux 8.1/IA64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake wget-1.8.2-3.1mdk.ppc.rpm
Mandrake Linux 8.0/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake wget-1.8.2-3.1mdk.ppc.rpm
Mandrake Linux 8.2/PPC
http://www.mandrakesecure.net/en/ftp.php -
Red Hat wget-1.8.2-4.6x.i386.rpm
ftp://updates.redhat.com/6.2/en/os/i386/wget-1.8.2-4.6x.i386.rpm -
Red Hat wget-1.8.2-4.70.i386.rpm
ftp://updates.redhat.com/7.0/en/os/i386/wget-1.8.2-4.70.i386.rpm -
Red Hat wget-1.8.2-4.71.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/wget-1.8.2-4.71.i386.rpm -
Red Hat wget-1.8.2-4.71.ia64.rpm
ftp://updates.redhat.com/7.1/en/os/ia64/wget-1.8.2-4.71.ia64.rpm -
Red Hat wget-1.8.2-4.72.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/wget-1.8.2-4.72.i386.rpm -
Red Hat wget-1.8.2-4.72.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/wget-1.8.2-4.72.ia64.rpm -
Red Hat wget-1.8.2-4.73.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/wget-1.8.2-4.73.i386.rpm -
Red Hat wget-1.8.2-5.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/wget-1.8.2-5.i386.rpm -
Trustix wget-1.8.2-4tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/1.5/RPMS/wget-1.8.2-4tr.i586 .rpm
References
WGet NLST Client Side File Overwriting Vulnerability
References:
References:
- RaQ XTR Patch Page (Sun)
- Directory Traversal Vulnerabilities in FTP Clients ("Steven M. Christey"
)