Rapid7 Vulnerability & Exploit Database

SuSE: wget 1.9.1-45.10.4

Back to Search

SuSE: wget 1.9.1-45.10.4

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
01/01/2005
Created
07/25/2018
Added
11/08/2005
Modified
11/18/2015

Description

This security update fixes security problems with wget.

  • HTTP redirect statements could be used to do a directory traversal and write to files outside of the current directory.
  • HTTP redirect statements could be used to overwrite dot (".") files potentially overwriting users .bashrc or similar files.

This update replaces dangerous directories and filenames by replacing the dot (".") with an underscore ("_").

The SUSE Linux 9.3 update also fixes the incorrectly encoded german translations.

Solution(s)

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;