Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53020
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2005:098 (wget)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to wget
announced via advisory MDKSA-2005:098.

Two vulnerabilities were found in wget. The first is that an HTTP
redirect statement could be used to do a directory traversal and
write to files outside of the current directory. The second is that
HTTP redirect statements could be used to overwrite dot ('.') files,
potentially overwriting the user's configuration files (such as
.bashrc, etc.).

The updated packages have been patched to help address these problems
by replacing dangerous directories and filenames containing the dot ('.')
character with an underscore ('_') character.

Affected versions: 10.0, 10.1, 10.2, Corporate 3.0,
Corporate Server 2.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2005:098

Risk factor : Medium

CVSS Score:
5.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-1487
BugTraq ID: 11871
http://www.securityfocus.com/bid/11871
Bugtraq: 20041209 wget: Arbitrary file overwriting/appending/creating and other vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=110269474112384&w=2
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=261755
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11682
http://www.redhat.com/support/errata/RHSA-2005-771.html
http://securitytracker.com/id?1012472
https://usn.ubuntu.com/145-1/
XForce ISS Database: wget-file-overwrite(18420)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18420
Common Vulnerability Exposure (CVE) ID: CVE-2004-1488
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9750
http://secunia.com/advisories/20960
SuSE Security Announcement: SUSE-SR:2006:016 (Google Search)
http://www.novell.com/linux/security/advisories/2006_16_sr.html
XForce ISS Database: wget-terminal-overwrite(18421)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18421
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.